Inconsistent name for term access query; information on taxonomy terms might have been disclosed to unprivileged users (CVE-2016-9449).
Confirmation forms allow external URLs to be injected (CVE-2016-9451).
{ "section": "core" }