WordPress · Wordpress · CVE-2020-28038
Name of the Vulnerable Software and Affected Versions:
WordPress versions prior to 5.5.2
Description:
The issue is related to insufficient protection measures for web page structures in the WordPress content management system. This can be exploited by a remote attacker to impact data integrity. The problem allows stored XSS via post slugs.
Recommendations:
For versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to post slug editing to minimize the risk of exploitation.