CVE-2020-35937: XSS
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to teamimportxmllayouts.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Stored Cross-Site Scripting (XSS) vulnerability in the Team Showcase plugin?
The vulnerability ID for the Stored Cross-Site Scripting (XSS) vulnerability in the Team Showcase plugin is CVE-2020-35937.
What is the severity of CVE-2020-35937?
The severity of CVE-2020-35937 is high with a severity value of 8.
Which software versions are affected by CVE-2020-35937?
The versions affected by CVE-2020-35937 are Pickplugins Post Grid up to and excluding version 2.0.73 and Pickplugins Team Showcase up to and excluding version 1.22.16.
How can remote attackers exploit CVE-2020-35937?
Remote authenticated attackers can exploit CVE-2020-35937 by importing layouts containing JavaScript via a remotely hosted crafted payload in the source parameter via AJAX.
Where can I find more information about CVE-2020-35937?
You can find more information about CVE-2020-35937 at the following link: [https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins/]