ZeroHour

CVE-2020-35946

PoC ×2
CVSS 3.1
5.4 medium
EPSS
<1%p56
Published
()
Modified
Description

An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.

Vendors
semperplugins
Products
all in one seo pack
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.