Automattic · Wordpress · CVE-2015-3429
**Name of the Vulnerable Software and Affected Versions**
Genericons versions prior to 3.3.1
WordPress versions prior to 4.2.2
**Description**
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a fragment identifier. This affects the example.html file in Genericons, which is used in WordPress.
**Recommendations**
For Genericons versions prior to 3.3.1, update to version 3.3.1 or later.
For WordPress versions prior to 4.2.2, update to version 4.2.2 or later.