CVE-2020-8426: XSS
Published Jan 28, 2020
·Updated
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
Affected Software
1 affected component
Elementor Website Builder WordPress<2.8.5
Event History
Jan 28, 2020
CVE Published
via MITRE·10:26 PM
Data Sourced
via MITRE·10:26 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-8426.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is Elementor Website Builder plugin version up to 2.8.5 for WordPress.
3
What is the severity of CVE-2020-8426?
The severity of CVE-2020-8426 is medium with a severity score of 5.4.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by targeting an authenticated user through a reflected XSS attack on the elementor-system-info page.
5
How can I fix CVE-2020-8426?
To fix CVE-2020-8426, update the Elementor plugin to version 2.8.5 or higher.