Official Product Homepageproduct
http://demo.themeftc.com/wibar CVE-2020-37235
MEDIUM
WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component
Record summary
CVE-2020-37235 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encoded script payloads through the ftc_brand_url input field to execute arbitrary JavaScript when users visit the brand page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Theme WibarBrowse themeftc / Theme Wibar | CVE List | 1.1.8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site ScriptingExploitDB exploitby Ilca Lucian FlorinNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37235 Product Referenceproduct
https://themeforest.net/item/wibar-responsive-woocommerce-wordpress-theme/20994798 ExploitDB-49107exploit
https://www.exploit-db.com/exploits/49107 VulnCheck Advisory: WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand ComponentThird-party advisory
https://www.vulncheck.com/advisories/wordpress-theme-wibar-stored-cross-site-scripting-via-brand-component