nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28650 CVE-2020-28650
MEDIUM
wpbakery page_builder Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2020-28650 has a selected CVSS score of 6.4 (medium).
Description
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 7, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
page_builderBrowse wpbakery / page_builder | VulnCheck | Version data not supplied | |
References
2wordfence.com
https://www.wordfence.com/blog/2020/10/vulnerability-exposes-over-4-million-sites-using-wpbakery