CVE-2020-24314: XSS
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24314?
CVE-2020-24314 has a medium severity due to its potential to enable reflected XSS attacks.
How do I fix CVE-2020-24314?
To fix CVE-2020-24314, update the Fahad Mahmood RSS Feed Widget Plugin to version 2.8.0 or higher.
What software is affected by CVE-2020-24314?
CVE-2020-24314 affects Fahad Mahmood RSS Feed Widget Plugin version 2.7.9 and lower.
How does CVE-2020-24314 work?
CVE-2020-24314 works by exposing reflected XSS due to unsanitized input from the 't' GET parameter.
Can CVE-2020-24314 be exploited without user interaction?
Yes, CVE-2020-24314 can be exploited through specially crafted URLs, allowing attackers to achieve XSS without direct user interaction.