CVE-2020-11025

MEDIUM

WordPress 4.7-5.4.1 - Authenticated Stored Cross-Site Scripting in Customizer Navigation

Title source: llm
STIX 2.1

Description

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

References (3)

Core 3
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4677

Scores

CVSS v3 5.8
EPSS 0.0143
EPSS Percentile 80.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N

Details

CWE
CWE-79
Status published
Products (3)
debian/debian_linux 9.0
debian/debian_linux 10.0
wordpress/wordpress 4.7 - 5.4.1
Published Apr 30, 2020
Tracked Since Feb 18, 2026