CyberRota
Back to database

CVE-2020-37235

MEDIUM · CVSS 6.4 EPSS 0.03% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-16 · Last synced: 2026-06-09

CyberRota Analysis

Saldırganın giriş yapmış olması gerekebilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2020-37235
Severity
MEDIUM
CVSS
6.4
EPSS
0.03%
WordPress Java

Original NVD Description

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encoded script payloads through the ftc_brand_url input field to execute arbitrary JavaScript when users visit the brand page.