Related Vulnerabilities: CVE-2017-6817  

An authenticated cross-site scripting (XSS) vulnerability has been discovered in in WordPress before 4.7.3 (wp-includes/embed.php) via YouTube URL Embeds.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

An authenticated cross-site scripting (XSS) vulnerability has been discovered in in WordPress before 4.7.3 (wp-includes/embed.php) via YouTube URL Embeds.

AVG-202 wordpress 4.7.2-1 4.7.3-1 Medium Fixed

16 Mar 2017 ASA-201703-14 AVG-202 wordpress Medium multiple issues

https://github.com/WordPress/WordPress/commit/419c8d97ce8df7d5004ee0b566bc5e095f0a6ca8