Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | - | 4.5.1.x |
plupload / plupload | - | 2.1.8.x |