CVE-2020-36722: Visual Composer <= 26.0 - Multiple Cross-Site Scripting
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36722?
CVE-2020-36722 is classified as a high-severity vulnerability due to its potential for exploitation through Cross-Site Scripting.
How do I fix CVE-2020-36722?
To fix CVE-2020-36722, update the Visual Composer plugin to version 26.1 or later.
What versions of the Visual Composer plugin are affected by CVE-2020-36722?
CVE-2020-36722 affects all versions of the Visual Composer plugin prior to version 26.1.
What type of vulnerability is CVE-2020-36722?
CVE-2020-36722 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient input sanitization.
Can CVE-2020-36722 be exploited remotely?
Yes, CVE-2020-36722 can be exploited remotely, allowing attackers to execute scripts in the browser of unsuspecting users.