PT-2020-5778 · WordPress · Wordpress
Karim El Ouerghemmi
+1
·
Published
2020-10-15
·
Updated
2024-03-06
·
CVE-2020-28038
CVSS v3.1
6.1
6.1
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WordPress versions prior to 5.5.2
Description:
The issue is related to insufficient protection measures for web page structures in the WordPress content management system. This can be exploited by a remote attacker to impact data integrity. The problem allows stored XSS via post slugs.
Recommendations:
For versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to post slug editing to minimize the risk of exploitation.
Exploit
Fix
XSS
Weakness Enumeration
Related Identifiers
BDU:2021-01737
BIT-WORDPRESS-2020-28038
BIT-WORDPRESS-MULTISITE-2020-28038
CVE-2020-28038
DLA-2429-1
DSA-4784-1
Affected Products
Wordpress
References · 46
- 🔥 https://github.com/nth347/CVE-2020-28032_PoC⭐ 4 🔗 2 · Exploit
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28038 · Security Note
- https://osv.dev/vulnerability/DLA-2429-1 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28035 · Security Note
- https://security-tracker.debian.org/tracker/DLA-2429-1 · Vendor Advisory
- https://security-tracker.debian.org/tracker/DSA-4784-1 · Vendor Advisory
- https://osv.dev/vulnerability/BIT-wordpress-2020-28038 · Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHVNK2WYAM3ZTCXTFSEIT56IKLVJHU3 · Vendor Advisory
- https://bdu.fstec.ru/vul/2021-01738 · Security Note
- https://osv.dev/vulnerability/DSA-4784-1 · Vendor Advisory
- https://bdu.fstec.ru/vul/2021-01762 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28032 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28040 · Security Note
- https://osv.dev/vulnerability/CVE-2020-28038 · Vendor Advisory
- https://ubuntu.com/security/CVE-2020-28038 · Vendor Advisory