Description
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
Remediation
References
Related Vulnerabilities
WordPress Plugin CloudFlare Multiple Cross-Site Scripting Vulnerabilities (1.3.20)
Atlassian Confluence Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2928)
Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-25149)
WordPress Plugin PHP Analytics Arbitrary File Upload (1.0.0.2)