CVE-2020-12742: Input Validation
Published May 13, 2020
·Updated
The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.
Affected Software
1 affected component
iubenda Iubenda-cookie-law-solution Wordpress<2.3.5
Remediation
Event History
May 13, 2020
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12742?
CVE-2020-12742 has been assigned a medium severity rating due to potential security risks associated with improper URL sanitization.
2
How do I fix CVE-2020-12742?
To fix CVE-2020-12742, update the iubenda-cookie-law-solution plugin to version 2.3.5 or later.
3
What are the potential risks associated with CVE-2020-12742?
CVE-2020-12742 can allow attackers to exploit improper URL sanitization, which may lead to malicious redirections.
4
Which versions of the iubenda-cookie-law-solution plugin are affected by CVE-2020-12742?
CVE-2020-12742 affects versions of the iubenda-cookie-law-solution plugin prior to 2.3.5.
5
Is CVE-2020-12742 specific to WordPress?
Yes, CVE-2020-12742 specifically affects the iubenda-cookie-law-solution plugin for WordPress.