PT-2020-20178 · WordPress · Gistpress
Published
2020-01-30
·
Updated
2020-02-03
·
CVE-2020-8498
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GistPress plugin versions prior to 3.0.2
Description
The issue exists in the shortcode functionality of the plugin via the
id parameter in the includes/class-gistpress.php file. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users, such as those who have the publish posts capability.Recommendations
For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the shortcode functionality to minimize the risk of exploitation. Avoid using the
id parameter in the affected shortcode until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gistpress