The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-02-21T08:50:37.298Z

Updated: 2024-08-04T17:30:08.559Z

Reserved: 2023-01-24T16:04:09.482Z

Link: CVE-2020-36656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-02-21T09:15:10.460

Modified: 2023-11-07T03:22:25.260

Link: CVE-2020-36656

cve-icon Redhat

No data.