Description
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
Remediation
References
Related Vulnerabilities
WordPress Plugin DMSGuestbook File Manipulation (1.17.4)
WordPress Plugin Wufoo Shortcode Cross-Site Scripting (1.47)
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10752)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0800)