Related Vulnerabilities: CVE-2017-5488  

A cross-site scripting (XSS) vulnerability has been discovered in wordpress via the plugin name or version header on update-core.php.

Severity High

Remote Yes

Type Cross-site scripting

Description

A cross-site scripting (XSS) vulnerability has been discovered in wordpress via the plugin name or version header on update-core.php.

AVG-142 wordpress 4.7-1 4.7.1-1 High Fixed FS#52555

15 Jan 2017 ASA-201701-22 AVG-142 wordpress High multiple issues

https://github.com/WordPress/WordPress/commit/c9ea1de1441bb3bda133bf72d513ca9de66566c2