PT-2026-41435 · Themeftc · Theme Wibar

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2020-37235

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encoded script payloads through the ftc brand url input field to execute arbitrary JavaScript when users visit the brand page.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-37235

Affected Products

Theme Wibar