In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
References
Link | Resource |
---|---|
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4mhg-j6fx-5g3c | Third Party Advisory |
https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updates | Vendor Advisory |
https://www.debian.org/security/2020/dsa-4677 | Third Party Advisory |
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4mhg-j6fx-5g3c | Third Party Advisory |
https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updates | Vendor Advisory |
https://www.debian.org/security/2020/dsa-4677 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:56
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.8 |
References | () https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4mhg-j6fx-5g3c - Third Party Advisory | |
References | () https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updates - Vendor Advisory | |
References | () https://www.debian.org/security/2020/dsa-4677 - Third Party Advisory |
Information
Published : 2020-04-30 22:15
Updated : 2024-11-21 04:56
NVD link : CVE-2020-11025
Mitre link : CVE-2020-11025
CVE.ORG link : CVE-2020-11025
JSON object : View
Products Affected
debian
- debian_linux
wordpress
- wordpress
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')