CVE-2020-35936: XSS
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to postgridimportxmllayouts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35936?
CVE-2020-35936 is a vulnerability in the Post Grid plugin before version 2.0.73 for WordPress that allows remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX.
What is the severity of CVE-2020-35936?
CVE-2020-35936 has a severity level of high.
How can CVE-2020-35936 be exploited?
CVE-2020-35936 can be exploited by remote authenticated attackers who can import layouts with JavaScript supplied through a crafted payload in the source parameter via AJAX.
Which software versions are affected by CVE-2020-35936?
Versions before 2.0.73 of the Post Grid plugin for WordPress and versions before 1.22.16 of the Team Showcase plugin for WordPress are affected by CVE-2020-35936.
How can I fix CVE-2020-35936?
To fix CVE-2020-35936, update the Post Grid plugin to version 2.0.73 or later and the Team Showcase plugin to version 1.22.16 or later.