CVE-2018-20977: XSS
Published Aug 21, 2019
·Updated
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
Affected Software
2 affected components
Brainstormforce Schema Wordpress<1.5.0
Brainstormforce Schema Wordpress<1.5.0
Event History
Aug 21, 2019
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-20977?
CVE-2018-20977 is a vulnerability in the all-in-one-schemaorg-rich-snippets plugin for WordPress that allows for cross-site scripting (XSS) attacks on the settings page.
2
How severe is CVE-2018-20977?
CVE-2018-20977 has a severity rating of 6.1, which is considered medium.
3
What software is affected by CVE-2018-20977?
The all-in-one-schemaorg-rich-snippets plugin for WordPress versions up to 1.5.0 is affected by CVE-2018-20977.
4
What is the Common Vulnerabilities and Exposures (CVE) reference for CVE-2018-20977?
The Common Vulnerabilities and Exposures (CVE) reference for CVE-2018-20977 is CVE-2018-20977.
5
How can I fix CVE-2018-20977?
To fix CVE-2018-20977, update the all-in-one-schemaorg-rich-snippets plugin to version 1.5.0 or later.