Description
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Stream Cross-Site Scripting (3.0.5)
Apache HTTP Server Other Vulnerability (CVE-2001-1449)
Joomla Cryptographic Issues Vulnerability (CVE-2011-4321)
phpBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-6506)
WordPress Plugin simpleSAMLphp Authentication Cross-Site Scripting (0.7.0)