Reflected XSS Vulnerability in Catch Breadcrumb Plugin for WordPress
CVE-2020-12054
6.1MEDIUM
What is CVE-2020-12054?
The Catch Breadcrumb plugin for WordPress, prior to version 1.5.4, is susceptible to a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this flaw by crafting a malicious URL that includes a harmful search query parameter 's', allowing them to execute arbitrary JavaScript in the user's browser. This vulnerability impacts not only the Catch Breadcrumb plugin but also 16 themes from the same author when the plugin is enabled, creating potential security risks for users who have these themes active. It's crucial for users to update to the latest version to mitigate this risk.