First published: Sun Jul 05 2020(Updated: )
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Car Rental System | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15535 is classified as a medium severity vulnerability due to the potential for persistent cross-site scripting (XSS).
To fix CVE-2020-15535, you should update the Bestsoftinc Car Rental System plugin to a version later than 1.3 that addresses the XSS vulnerability.
CVE-2020-15535 enables persistent cross-site scripting (XSS) attacks through the registration fields of the affected plugin.
CVE-2020-15535 affects all versions of the Bestsoftinc Car Rental System plugin up to and including version 1.3.
Users and administrators of the Bestsoftinc Car Rental System plugin on WordPress should be concerned about CVE-2020-15535 due to the risk of XSS attacks.