In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-04-30T22:10:11

Updated: 2024-08-04T11:21:14.581Z

Reserved: 2020-03-30T00:00:00

Link: CVE-2020-11025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-30T22:15:11.887

Modified: 2024-11-21T04:56:36.933

Link: CVE-2020-11025

cve-icon Redhat

No data.