First published: Fri Jan 01 2021(Updated: )
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Post Grid | <2.0.73 | |
PickPlugins Team Showcase | <1.22.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Stored Cross-Site Scripting (XSS) vulnerability in the Team Showcase plugin is CVE-2020-35937.
The severity of CVE-2020-35937 is high with a severity value of 8.
The versions affected by CVE-2020-35937 are Pickplugins Post Grid up to and excluding version 2.0.73 and Pickplugins Team Showcase up to and excluding version 1.22.16.
Remote authenticated attackers can exploit CVE-2020-35937 by importing layouts containing JavaScript via a remotely hosted crafted payload in the source parameter via AJAX.
You can find more information about CVE-2020-35937 at the following link: [https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins/]