CVE-2020-11025

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-11025
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11025.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-11025
Aliases
Downstream
Related
  • GHSA-4mhg-j6fx-5g3c
Published
2020-04-30T22:15:11Z
Modified
2025-11-03T18:34:47Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

References

Affected packages

Git / github.com/wordpress/wordpress-develop

Affected ranges

Type
GIT
Repo
https://github.com/wordpress/wordpress-develop
Events

Git / github.com/wordpress/wordpress

Affected ranges

Type
GIT
Repo
https://github.com/wordpress/wordpress
Events