Record summary

CVE-2020-17362 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2020-17362Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 281 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMNova Lite < 1.3.9 - Cross-Site ScriptingCVSS 6.1

Nova Lite before 1.3.9 for WordPress is susceptible to reflected cross-site scripting via search.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to Nova Lite version 1.3.9 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2020cvewordpressxsswp-pluginwpscanunauththemeinprogressvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:themeinprogress:nova_lite:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2