Description
wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Mailchimp Security Bypass (2.1.3)
WordPress 'wp-admin/admin.php' Module Configuration Security Bypass Vulnerability (0.6.2 - 2.8)
Oracle JRE CVE-2012-3342 Vulnerability (CVE-2012-3342)
Ruby on Rails CVE-2024-28103 Vulnerability (CVE-2024-28103)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2017-5340)