CyberSec.Space Logo
返回 CVE 浏览器

CVE-2020-35936

HIGH
7.5
CVSS Severity Score
EPSS Score0.0390%
EPSS Percentile16.04th
Published2021年1月1日
Last Modified2024年11月21日

Vulnerability Description

Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

Affected Platforms (CPE)

📦
Pickplugins

Post Grid

< 2.0.73
📦
Pickplugins

Team Showcase

< 1.22.16

References & Advisories

相关漏洞威胁