PT-2020-5778 · WordPress · Wordpress
Karim El Ouerghemmi
+1
·
Published
2020-10-15
·
Updated
2024-03-06
·
CVE-2020-28038
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WordPress versions prior to 5.5.2
Description:
The issue is related to insufficient protection measures for web page structures in the WordPress content management system. This can be exploited by a remote attacker to impact data integrity. The problem allows stored XSS via post slugs.
Recommendations:
For versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to post slug editing to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress