CVE-2016-10706: XSS
Published Jan 12, 2018
·Updated
The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.
Affected Software
1 affected component
Automattic Jetpack Wordpress<4.0.3
Event History
Jan 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
This vulnerability is identified as CVE-2016-10706.
2
What is the severity of CVE-2016-10706?
CVE-2016-10706 has a severity level of medium.
3
Which software is affected by CVE-2016-10706?
The Jetpack plugin before version 4.0.3 for WordPress is affected by CVE-2016-10706.
4
How can an attacker exploit CVE-2016-10706?
An attacker can exploit CVE-2016-10706 by crafting a malicious Vimeo link.
5
Is there a fix available for CVE-2016-10706?
Yes, a fix is available in version 4.0.3 of the Jetpack plugin for WordPress.