CVE-2019-20141

MEDIUM NUCLEI

Laborator Neon 2.0 - Reflected Cross-Site Scripting via Autosuggest Remote q Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-20141 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.

Nuclei Templates (1)

WordPress Laborator Neon Theme 2.0 - Cross-Site Scripting
MEDIUMby knassar702

References (2)

Core 2
Core References
Broken Link, Exploit, Third Party Advisory x_refsource_misc
https://knassar7o2.blogspot.com/2019/12/neon-dashboard-xss-reflected.html
Broken Link x_refsource_misc
https://knassar702.github.io/cve/neon/

Scores

CVSS v3 6.1
EPSS 0.0434
EPSS Percentile 89.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
laborator/neon 2.0
Published Dec 30, 2019
Tracked Since Feb 18, 2026