WordPress 4.7.3 release is out to fix six security issues, including three cross-site scripting (XSS) vulnerabilities. The flaws were discovered by the security experts Chris Andr Dale, Yorick Koster, Simon P. Briggs, Marc Montpas and a user that goes online with the moniker Delta. The XSS vulnerabilities can be exploited via media file metadata, video URLs in YouTube embeds, and taxonomy term names. CSRF vulnerability discovered in July 2016 remains unpatched.”]
Source: http://securityaffairs.co/wordpress/56953/hacking/wordpress-4-7-3-security.html

