CVE-2020-7228: XSS
Published Jan 22, 2020
·Updated
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
Affected Software
1 affected component
CodePeople Calculated Fields Form Wordpress<=1.0.353
Event History
Jan 22, 2020
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7228?
CVE-2020-7228 has been rated as a high severity vulnerability due to its potential for exploitation by authenticated users.
2
How do I fix CVE-2020-7228?
To fix CVE-2020-7228, update the Calculated Fields Form plugin to version 1.0.354 or later.
3
Who is affected by CVE-2020-7228?
CVE-2020-7228 affects users of the Calculated Fields Form plugin for WordPress versions up to and including 1.0.353.
4
What type of vulnerability is CVE-2020-7228?
CVE-2020-7228 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2020-7228 be exploited remotely?
CVE-2020-7228 cannot be exploited remotely and requires an authenticated user to initiate the attack.