Reflected XSS Vulnerability in Catch Breadcrumb Plugin for WordPress
CVE-2020-12054
6.1MEDIUM
Summary
The Catch Breadcrumb plugin for WordPress, prior to version 1.5.4, is susceptible to a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this flaw by crafting a malicious URL that includes a harmful search query parameter 's', allowing them to execute arbitrary JavaScript in the user's browser. This vulnerability impacts not only the Catch Breadcrumb plugin but also 16 themes from the same author when the plugin is enabled, creating potential security risks for users who have these themes active. It's crucial for users to update to the latest version to mitigate this risk.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved