Description
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
Remediation
References
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-20151)
MySQL NULL Pointer Dereference Vulnerability (CVE-2020-1971)
MySQL CVE-2015-0391 Vulnerability (CVE-2015-0391)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.11)
WordPress Plugin Import XML and RSS Feeds Arbitrary File Upload (2.1.5)