CVE-2020-25378: XSS
Published Sep 14, 2020
·Updated
Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter.
Affected Software
1 affected component
Accesspressthemes Wp Floating Menu Wordpress=1.3.0
Event History
Sep 14, 2020
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-25378.
2
What is the affected software?
The affected software is AccessPress Themes WP Floating Menu version 1.3.0.
3
What is the severity of CVE-2020-25378?
The severity of CVE-2020-25378 is medium with a CVSS score of 6.1.
4
How does CVE-2020-25378 impact the affected software?
CVE-2020-25378 allows for Cross Site Scripting (XSS) attacks through the id GET parameter in AccessPress Themes WP Floating Menu version 1.3.0.
5
Is there a fix for CVE-2020-25378?
At the moment, there is no known fix for CVE-2020-25378. It is recommended to update to the latest version of the plugin or apply any patches released by the vendor.