ThreatPress

WordPress Vulnerabilities Database

Back

WordPress <= 4.2.3 - XSS #1

Product
WordPress
Description
This vulnerability exists in the "refreshAdvancedAccessibilityOfItem" function. It allows an attacker to inject arbitrary web script or HTML via an accessibility-helper title. Related records: http://db.threatpress.com/vulnerability/wordpress/wordpress-4-2-3-xss-2
Solution
Update WordPress.
Classification
Type XSS (Cross Site Scripting)
OWASP Top 10 A3: Cross Site Scripting (XSS)
References
CVE Mitre
CVE
Name CVE-2015-5733
Versions
Affected In <= 4.2.3
Fixed In 4.2.4
Disclosure date
2015-08-04