CVE-2017-5490 | WordPress up to 4.7.0 class-wp-theme.php cross site scripting (EDB-40968 / Nessus ID 96606)
A vulnerability identified as problematic has been detected in WordPress up to 4.7.0. Affected by this issue is some unknown functionality of the file wp-includes/class-wp-theme.php. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2017-5490. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
You should upgrade the affected component.