Boletines de Vulnerabilidades

XSS Flaw Impacting 100,000 Sites Patched in KingComposer


Información sobre el sistema

   
Software afectado Wordpress

Descripción

On June 15, 2020, our Threat Intelligence team was made aware of a number of access control vulnerabilities that had recently been disclosed in KingComposer, a WordPress plugin installed on over 100,000 sites. During our investigation of these vulnerabilities, we discovered an unpatched reflected Cross-Site Scripting(XSS) vulnerability. Wordfence Premium customers received a new firewall rule […]

More info:

https://www.wordfence.com/blog/2020/07/xss-flaw-impacting-100000-sites-patched-in-kingcomposer/

Identificadores estándar

Propiedad Valor
CVE CVE-2020-15299.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2020-07-11

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT