CVE-2020-35937

Team Showcase <= 1.22.15 - Stored Cross-Site Scripting

highImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
7.5
CVSS Score
7.5
CVSS Score
high
Severity
1.22.16
Patched in
1223d
Time to patch

Description

Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
High
Confidentiality
High
Integrity
High
Availability

Technical Details

Affected versions<1.22.16
PublishedSeptember 17, 2020
Last updatedJanuary 22, 2024
Affected pluginteam

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.