1
Candidate: CVE-2016-5834
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5834
5
https://wordpress.org/news/2016/06/wordpress-4-5-3/
6
https://marc.info/?l=oss-security&m=146670813911482&w=2
8
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link
9
function in wp-includes/post-template.php in WordPress before 4.5.3 allows
10
remote attackers to inject arbitrary web script or HTML via a crafted
11
attachment name, a different vulnerability than CVE-2016-5833.
16
Discovered-by: Divyesh Prajapati
20
upstream_wordpress: released (4.5.3+dfsg-1)
21
precise_wordpress: ignored (reached end-of-life)
22
precise/esm_wordpress: DNE (precise was needed)
23
trusty_wordpress: needed
24
vivid/stable-phone-overlay_wordpress: DNE
25
vivid/ubuntu-core_wordpress: DNE
26
wily_wordpress: ignored (reached end-of-life)
27
xenial_wordpress: needed
28
yakkety_wordpress: ignored (reached end-of-life)
29
zesty_wordpress: ignored (reached end-of-life)
30
artful_wordpress: needed
31
bionic_wordpress: needed
32
devel_wordpress: needed