Reflected XSS Vulnerability in PageLayer Plugin for WordPress
CVE-2020-36383
6.1MEDIUM
What is CVE-2020-36383?
The PageLayer plugin for WordPress, prior to version 1.3.5, is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability through the font-size parameter. This flaw could allow attackers to execute arbitrary JavaScript code in the context of a victim's browser, potentially leading to unauthorized actions or data theft. Website administrators are urged to update the plugin to the latest version to mitigate the risks associated with this vulnerability.