Description
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
Remediation
References
Related Vulnerabilities
RubyGems Cryptographic Issues Vulnerability (CVE-2013-4363)
MySQL CVE-2015-4791 Vulnerability (CVE-2015-4791)
MediaWiki Improper Access Control Vulnerability (CVE-2016-6337)
IBM RTC Cleartext Storage of Sensitive Information Vulnerability (CVE-2021-29786)
Envoy Proxy Insufficient Verification of Data Authenticity Vulnerability (CVE-2020-8660)