CVE-2020-28038: XSS
Published Oct 31, 2020
·Updated
WordPress before 5.5.2 allows stored XSS via post slugs.
Affected Software
7 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Oct 31, 2020
CVE Published
via MITRE·12:59 AM
Data Sourced
via MITRE·12:59 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this WordPress vulnerability?
The vulnerability ID for this WordPress vulnerability is CVE-2020-28038.
2
What is the title of this vulnerability?
The title of this vulnerability is 'WordPress before 5.5.2 allows stored XSS via post slugs.'
3
What is the severity rating of CVE-2020-28038?
The severity rating of CVE-2020-28038 is medium with a value of 6.1.
4
How does this vulnerability affect WordPress?
This vulnerability affects WordPress versions before 5.5.2.
5
How can I fix CVE-2020-28038?
To fix CVE-2020-28038, you should update your WordPress installation to version 5.5.2 or higher.