CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects WordPress, Java.
CVE
CVE-2020-11508
Severity
MEDIUM
CVSS
5.4
EPSS
0.78%
WordPress Java
Original NVD Description
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.
Related CVEs
Other vulnerabilities affecting the same vendor(s)