Record summary

CVE-2019-20141 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Laborator Neon Theme 2.0 - Cross-Site ScriptingCVSS 6.1

WordPress Laborator Neon theme 2.0 contains a cross-site scripting vulnerability via the data/autosuggest-remote.php q parameter.

Impact

Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing administrative actions on behalf of users.

Remediation

Apply the latest security patch or update provided by the theme developer to fix the XSS vulnerability.

WeaknessesCWE-79
Authorsknassar702
Template tagscve2019cvexsslaboratorwordpressvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:laborator:neon:2.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3