CVE-2017-5490: XSS
Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted directory name of a theme, related to wp-admin/includes/class-theme-installer-skin.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/wp-includes/class-wp-theme.phpto a version that resolves this vulnerability.Fixed in 4.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5490?
CVE-2017-5490 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS).
How do I fix CVE-2017-5490?
To mitigate CVE-2017-5490, you should update your WordPress installation to version 4.7.1 or later.
What types of attacks can CVE-2017-5490 be used for?
CVE-2017-5490 can be exploited by attackers to perform cross-site scripting (XSS) attacks, injecting malicious scripts into web pages.
Which versions of WordPress are affected by CVE-2017-5490?
CVE-2017-5490 affects all WordPress versions prior to 4.7.1.
Who is at risk due to CVE-2017-5490?
Website administrators and users of WordPress prior to version 4.7.1 are at risk due to CVE-2017-5490.