CVE-2018-5776: XSS
Published Jan 18, 2018
·Updated
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
Affected Software
1 affected component
WordPress<4.9.2
Remediation
Event History
Jan 18, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5776?
CVE-2018-5776 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2018-5776?
To fix CVE-2018-5776, update your WordPress installation to version 4.9.2 or later.
3
What type of vulnerability is CVE-2018-5776?
CVE-2018-5776 is a cross-site scripting (XSS) vulnerability found in WordPress.
4
Which versions of WordPress are affected by CVE-2018-5776?
CVE-2018-5776 affects all versions of WordPress prior to 4.9.2.
5
What components of WordPress are impacted by CVE-2018-5776?
CVE-2018-5776 impacts the Flash fallback files in the MediaElement component under wp-includes/js/mediaelement.