CVE-2020-35944: XSS
Published Jan 1, 2021
·Updated
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayersettingspage function is vulnerable to CSRF, which can lead to XSS.
Affected Software
1 affected component
PageLayer Pagelayer WordPress<1.1.2
Event History
Jan 1, 2021
CVE Published
via MITRE·03:28 AM
Data Sourced
via MITRE·03:28 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-35944.
2
What is the severity of CVE-2020-35944?
The severity of CVE-2020-35944 is high with a score of 8.8.
3
What is the affected software?
The affected software is Pagelayer plugin before version 1.1.2 for WordPress.
4
What is the risk of CVE-2020-35944?
CVE-2020-35944 poses a risk of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) attacks.
5
How can I fix CVE-2020-35944?
To fix CVE-2020-35944, update the Pagelayer plugin to version 1.1.2 or later.