MEDIUM
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site
Published Dec 2, 2017
5.4
MEDIUMCVSS 3.0
EPSS 1.97%
Description
Affected products
Remediation
References (7)
Change history (0)
No recorded changes yet.