First published: Fri Jan 01 2021(Updated: )
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pagelayer | <1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-35944.
The severity of CVE-2020-35944 is high with a score of 8.8.
The affected software is Pagelayer plugin before version 1.1.2 for WordPress.
CVE-2020-35944 poses a risk of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) attacks.
To fix CVE-2020-35944, update the Pagelayer plugin to version 1.1.2 or later.