This potentially enables an HTTP response splitting attack which, in turn, can lead to reflected XSS attack for remote code execution. The flaw was fixed in versions 9.4.5 Patch1 ( released on ...
The flaw, a reflected cross-site scripting (XSS ... characters and a limited set of symbols in the popup-selector argument. This prevents common XSS attack methods from exploiting the flaw. WordPress ...