PT-2020-5800 · WordPress · Wordpress

·

CVE-2020-28034

·

Published

2020-10-15

·

Updated

2024-03-06

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WordPress versions prior to 5.5.2
Description: The issue is related to insufficient protection measures for web page structures in the WordPress content management system, allowing for potential data integrity impact by a remote attacker. It is associated with global variables and can lead to cross-site scripting (XSS).
Recommendations: For WordPress versions prior to 5.5.2, update to version 5.5.2 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01763
BIT-WORDPRESS-2020-28034
BIT-WORDPRESS-MULTISITE-2020-28034
CVE-2020-28034
DLA-2429-1
DSA-4784-1

Affected Products

Wordpress