CVE-2019-16217 | WordPress up to 5.2.2 Media Upload wp_ajax_upload_attachment cross site scripting (Bug 45936 / Nessus ID 259385)
A vulnerability marked as problematic has been reported in WordPress up to 5.2.2. Impacted is an unknown function of the component Media Upload. Performing manipulation of the argument wp_ajax_upload_attachment results in cross site scripting.
This vulnerability was named CVE-2019-16217. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.