CVE-2015-3440 | WordPress up to 4.2.0 Comment wp-includes/wp-db.php Stored cross site scripting (News 131644 / EDB-36844)
A vulnerability was found in WordPress up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file wp-includes/wp-db.php of the component Comment Handler. The manipulation leads to cross site scripting (Stored).
This vulnerability is known as CVE-2015-3440. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.