Vulnerability Description
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pickplugins | Post Grid | < 2.0.73 |
| Pickplugins | Team Showcase | < 1.22.16 |
Related Weaknesses (CWE)
References
- https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-griExploitThird Party Advisory
- https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-griExploitThird Party Advisory
FAQ
What is CVE-2020-35937?
CVE-2020-35937 is a vulnerability with a CVSS score of 7.5 (HIGH). Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a re...
How severe is CVE-2020-35937?
CVE-2020-35937 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35937?
Check the references section above for vendor advisories and patch information. Affected products include: Pickplugins Post Grid, Pickplugins Team Showcase.