Description
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social LikeBox & Feed Cross-Site Scripting (2.8.4)
WordPress Plugin WP-Lister Lite for Amazon Directory Traversal (0.9.6.35)
WordPress Plugin BackUpWordPress Unspecified Vulnerability (3.12)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.22)
Jenkins Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2020-2105)