CVE-2020-36172: XSS
Published Jan 6, 2021
·Updated
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.
Affected Software
1 affected component
Advancedcustomfields Advanced Custom Fields Wordpress<5.8.12
Event History
Jan 6, 2021
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Advanced Custom Fields plugin?
The vulnerability ID for the Advanced Custom Fields plugin is CVE-2020-36172.
2
What is the severity level of CVE-2020-36172?
The severity level of CVE-2020-36172 is medium.
3
How does the Advanced Custom Fields plugin mishandle the escaping of strings?
The Advanced Custom Fields plugin mishandles the escaping of strings in Select2 dropdowns.
4
What is the potential impact of CVE-2020-36172?
CVE-2020-36172 has the potential to lead to cross-site scripting (XSS) attacks.
5
How can I fix the vulnerability in the Advanced Custom Fields plugin?
To fix the vulnerability in the Advanced Custom Fields plugin, update to version 5.8.12 or newer.