In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-04-30T22:10:11
Updated: 2024-08-04T11:21:14.581Z
Reserved: 2020-03-30T00:00:00
Link: CVE-2020-11025
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-30T22:15:11.887
Modified: 2024-11-21T04:56:36.933
Link: CVE-2020-11025
Redhat
No data.