CyberRota
Back to database

CVE-2020-37233

MEDIUM · CVSS 6.4 EPSS 0.03% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-16 · Last synced: 2026-06-09

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2020-37233
Severity
MEDIUM
CVSS
6.4
EPSS
0.03%
WordPress

Original NVD Description

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onload that execute when administrators or privileged users preview or view the affected page content, enabling session hijacking and persistent phishing attacks.