CVE-2015-3440 | WordPress 3.9.3/4.1.1/4.1.2/4.2 Comment Stored cross site scripting (EDB-36844 / Nessus ID 83138)
A vulnerability was found in WordPress 3.9.3/4.1.1/4.1.2/4.2. It has been declared as problematic. This vulnerability affects unknown code of the component Comment Handler. The manipulation leads to cross site scripting (Stored).
This vulnerability was named CVE-2015-3440. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.