CVE-2016-1564 | WordPress up to 4.4.0 class-wp-theme.php cross site scripting (News 36185 / Nessus ID 87900)
A vulnerability, which was classified as problematic, has been found in WordPress up to 4.4.0. Affected by this issue is some unknown functionality of the file wp-includes/class-wp-theme.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2016-1564. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.