Record summary

CVE-2020-37225 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 13, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List0.9.31affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site ScriptingExploitDB exploitby mqtNot analyzed1 file
ExploitDB

PoC details

References

6