CVE-2020-15020: XSS
Published Aug 31, 2020
·Updated
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
Affected Software
1 affected component
Elementor Website Builder WordPress<=2.9.13
Event History
Aug 31, 2020
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Elementor plugin issue?
The vulnerability ID for this Elementor plugin issue is CVE-2020-15020.
2
What is the severity level of CVE-2020-15020?
The severity level of CVE-2020-15020 is medium, with a CVSS score of 5.4.
3
What is the affected software?
The affected software is Elementor Website Builder for WordPress, up to version 2.9.13.
4
How can an attacker exploit CVE-2020-15020?
An authenticated attacker can achieve stored XSS via the Name Your Template field.
5
Are there any references for CVE-2020-15020?
Yes, you can find references for CVE-2020-15020 at the following URLs: [reference1] [reference2].