CVE-2020-15535: XSS
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15535?
CVE-2020-15535 is classified as a medium severity vulnerability due to the potential for persistent cross-site scripting (XSS).
How do I fix CVE-2020-15535?
To fix CVE-2020-15535, you should update the Bestsoftinc Car Rental System plugin to a version later than 1.3 that addresses the XSS vulnerability.
What kind of attack does CVE-2020-15535 enable?
CVE-2020-15535 enables persistent cross-site scripting (XSS) attacks through the registration fields of the affected plugin.
Which versions of the Car Rental System plugin are affected by CVE-2020-15535?
CVE-2020-15535 affects all versions of the Bestsoftinc Car Rental System plugin up to and including version 1.3.
Who should be concerned about CVE-2020-15535?
Users and administrators of the Bestsoftinc Car Rental System plugin on WordPress should be concerned about CVE-2020-15535 due to the risk of XSS attacks.