Description
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Remediation
References
Related Vulnerabilities
Drupal Core 9.2.x Multiple Security Bypass Vulnerabilities (9.2.0 - 9.2.5)
WordPress Plugin Drug Search Cross-Site Scripting (1.0.0)
Apache Tomcat Cryptographic Issues Vulnerability (CVE-2011-5064)
WordPress Plugin WP Publication Archive 'file' Parameter Directory Traversal (2.3)
Internet Information Services Other Vulnerability (CVE-2005-2678)