CVE-2020-11025
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed.
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wordpress/wordpress · debian/debian linux
- Source
- security-advisories@github.com
References
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4mhg-j6fx-5g3cThird Party Advisory
- https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updatesVendor Advisory
- https://www.debian.org/security/2020/dsa-4677Third Party Advisory
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4mhg-j6fx-5g3cThird Party Advisory
- https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updatesVendor Advisory
- https://www.debian.org/security/2020/dsa-4677Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.