CVE-2020-35933: XSS
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpcrender AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encodedoptions parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35933?
The severity of CVE-2020-35933 is medium with a CVSSv3 score of 6.5.
Which software versions are affected by CVE-2020-35933?
The Newsletter plugin before version 6.8.2 for WordPress is affected by CVE-2020-35933.
What is the vulnerability type of CVE-2020-35933?
CVE-2020-35933 is a Reflected Authenticated Cross-Site Scripting (XSS) vulnerability.
How can remote attackers exploit CVE-2020-35933?
Remote attackers can exploit CVE-2020-35933 by tricking a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string.
Is there a fix available for CVE-2020-35933?
Yes, the fix for CVE-2020-35933 is to update to version 6.8.2 or newer of the Newsletter plugin for WordPress.