CVE-2017-6818: WordPress
Medium severity, CVSS 6.1. EPSS: 2.6% chance of exploitation in the next 30 days.
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
Affected products
- WordPress WordPress: up to and including 4.7.2
Published 2017-03-12. Last modified 2026-06-17.