CVE-2020-4049: Authenticated self-XSS via theme uploads in WordPress
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this WordPress vulnerability?
The vulnerability ID for this WordPress vulnerability is CVE-2020-4049.
What is the severity level of CVE-2020-4049?
CVE-2020-4049 has a severity level of low.
How can this vulnerability be exploited?
This vulnerability can be exploited by crafting the name of a theme folder in a way that could lead to JavaScript execution on the themes page in /wp-admin.
Who can exploit this vulnerability?
An admin with the ability to upload themes can exploit this vulnerability.
How can I fix CVE-2020-4049?
To fix CVE-2020-4049, update to WordPress version 5.4.2 or later.