Medium severity4.8NVD Advisory· Published Jan 5, 2017· Updated Jun 17, 2026
CVE-2016-7168
CVE-2016-7168
Description
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: <=4.6
- (no CPE)range: <4.6.1
Patches
Vulnerability mechanics
References
9- codex.wordpress.org/Version_4.6.1nvdPatch
- github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0nvdPatch
- wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/nvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2016/09/08/19nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/09/08/24nvdThird Party Advisory
- www.securityfocus.com/bid/92841nvdThird Party AdvisoryVDB Entry
- sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.htmlnvdThird Party Advisory
- www.debian.org/security/2016/dsa-3681nvd
- wpvulndb.com/vulnerabilities/8615nvd
News mentions
0No linked articles in our index yet.