Description
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
Remediation
References
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0165)
WordPress Plugin Forget About Shortcode Buttons Cross-Site Scripting (1.1.1)
WordPress Plugin Contact Form Check Tester Cross-Site Scripting (1.0.2)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.8)