Description
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-0552 Vulnerability (CVE-2012-0552)
Envoy Proxy Reachable Assertion Vulnerability (CVE-2022-29228)
WordPress Other Vulnerability (CVE-2006-0985)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (6.0)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19039)