Intrusion Prevention

WordPress.Shortcode.Tags.XSS

Description

This indicates an attack attempt against a Cross-Site Scripting vulnerability in Wordpress.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. A remote attacker may be able to exploit this to execute arbitrary script code within the context of the application, via crafted HTTP requests.

Affected Products

WordPress versions 4.3 and earlier

Impact

System Compromise: Remote attackers can execute arbitrary script code on vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
https://wordpress.org/download/

CVE References

CVE-2015-5714