Cross-Site Scripting Vulnerability in SportsPress Plugin for WordPress
CVE-2020-13892
5.4MEDIUM
Summary
The SportsPress plugin prior to version 2.7.2 is susceptible to Cross-Site Scripting (XSS) attacks. This vulnerability enables attackers to inject malicious scripts into webpages viewed by users, potentially compromising site integrity and user data. Ensuring that the plugin is updated to the latest version is critical for maintaining robust security against such threats.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved