Description
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
Remediation
References
Related Vulnerabilities
RubyGems Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-0899)
WordPress Plugin Easy Author Image Information Disclosure (1.5)
WordPress Plugin VDZ CallBack Cross-Site Scripting (1.14.5)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4193)