5.4
CVSSv3

CVE-2020-11025

Published: 30/04/2020 Updated: 18/08/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #959391 wordpress: CVE-2020-11025 CVE-2020-11026 CVE-2020-11027 CVE-2020-11028 CVE-2020-11029 CVE-2020-11030 Package: src:wordpress; Maintainer for src:wordpress is Craig Small <csmall@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 1 May 2020 20:21:01 UTC Sever ...
Several vulnerabilities were discovered in Wordpress, a web blogging tool They allowed remote attackers to perform various Cross-Side Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create files on the server, disclose private information, create open redirects, poison cache, and bypass authorization access and input sanitation For ...

Github Repositories

Docker image with Ubuntu CVE Tracker, Security Tools, and UMT installed to assist in CVE analysis and triage.

About Docker image with Ubuntu CVE Tracker, Security Tools, and UMT installed to assist in Ubuntu CVE analysis and triage You can find the list of available Ubuntu CVE's that need triaged at peoplecanonicalcom/~ubuntu-security/cve/universehtml CVE Tools installed & configured Ubuntu CVE Tracker Ubuntu Security Tools Ubuntu QA Tools Installation Method

Docker image with Ubuntu CVE Tracker, Security Tools, and UMT installed to assist in CVE analysis and triage.

About Docker image with Ubuntu CVE Tracker, Security Tools, and UMT installed to assist in Ubuntu CVE analysis and triage You can find the list of available Ubuntu CVE's that need triaged at peoplecanonicalcom/~ubuntu-security/cve/universehtml CVE Tools installed & configured Ubuntu CVE Tracker Ubuntu Security Tools Ubuntu QA Tools Installation Method