CVE-2020-36853: 10WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change
The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36853?
CVE-2020-36853 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2020-36853?
To fix CVE-2020-36853, update the 10WebMapBuilder plugin to version 1.0.64 or later.
Who is affected by CVE-2020-36853?
CVE-2020-36853 affects WordPress sites using the 10WebMapBuilder plugin versions 1.0.63 and earlier.
What type of vulnerability is CVE-2020-36853?
CVE-2020-36853 is a Stored Cross-Site Scripting vulnerability that allows attackers to inject malicious scripts.
What can attackers do with CVE-2020-36853?
Attackers exploiting CVE-2020-36853 can potentially execute arbitrary JavaScript in the context of the user's session.