AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-35936

HIGH · CVSS 7.5 EPSS 1.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-01-01 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-35936
Severity
HIGH
CVSS
7.5
EPSS
1.65%
WordPress Java

Original NVD Description

Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

Related CVEs

Other vulnerabilities affecting the same vendor(s)