CVE-2020-35946
PoC ×2—CVSS 3.1
5.4 medium
EPSS
<1%p56
Published
()
Modified
Description
An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.
- Vendors
- semperplugins
- Products
- all in one seo pack
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.