In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
References
Link | Resource |
---|---|
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4mhg-j6fx-5g3c | Third Party Advisory |
https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updates | Vendor Advisory |
https://www.debian.org/security/2020/dsa-4677 | Third Party Advisory |
Information
Published : 2020-04-30 15:15
Updated : 2020-08-18 08:05
NVD link : CVE-2020-11025
Mitre link : CVE-2020-11025
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
debian
- debian_linux
wordpress
- wordpress