Cross-Site Scripting Flaw in WL-Enq Product by WordPress
CVE-2020-5559

6.1MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
25 March 2020

What is CVE-2020-5559?

A cross-site scripting vulnerability exists in WL-Enq versions 1.11 and 1.12, which may allow remote attackers to inject arbitrary web scripts or HTML into users' browsers via unspecified vectors. This could lead to the execution of malicious scripts, compromising the security of the affected web applications and potentially allowing for unauthorized data access.

Affected Version(s)

WL-Enq 1.11 and 1.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.