Description
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Download Manager Remote Code Execution (2.7.4)
WordPress Plugin Broken Link Manager Multiple Vulnerabilities (0.4.5)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (32.0.5)
WordPress Plugin Juiz Social Post Sharer Multiple Cross-Site Scripting Vulnerabilities (1.3.3.7)