CVE-2020-24314
RSS Feed Widget <= 2.8.0 - Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
Fahad Mahmood RSS Feed Widget Plugin versiones v2.7.9 y anteriores, no sanea el valor del parámetro GET "t" antes de repetirlo dentro de una etiqueta de entrada. Esto resulta en una vulnerabilidad de tipo XSS reflejado que atacantes pueden explotar con una URL especialmente diseñada
Fahad Mahmood RSS Feed Widget Plugin v2.8.0 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-10 CVE Published
- 2020-08-13 CVE Reserved
- 2023-05-12 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/rss-feed-widget/advanced | Product |
URL | Date | SRC |
---|---|---|
https://zeroaptitude.com/zerodetail/wordpress-plugin-bug-hunting-part-1 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rss Feed Widget Project Search vendor "Rss Feed Widget Project" | Rss Feed Widget Search vendor "Rss Feed Widget Project" for product "Rss Feed Widget" | <= 2.7.9 Search vendor "Rss Feed Widget Project" for product "Rss Feed Widget" and version " <= 2.7.9" | wordpress |
Affected
|