WordPress before 4.9.1 contains a cross-site scripting caused by not requiring unfiltered_html capability for uploading .js files in functions.php, letting remote attackers execute scripts via crafted files, exploit requires upload permissions.
id: CVE-2017-17092
info:
name: WordPress < 4.9.1 - Authenticated JavaScript File Upload
author:
...