Boletines de Vulnerabilidades

High Severity Vulnerability Patched in TC Custom JavaScript


Información sobre el sistema

   
Software afectado Wordpress

Descripción

On June 12, 2020, Wordfence Threat Intelligence discovered an unauthenticated stored Cross-Site Scripting(XSS) vulnerability in TC Custom JavaScript, a WordPress plugin with over 10,000 installations. Wordfence Premium customers received a new firewall rule to provide protection against attacks targeting this vulnerability the same day. Wordfence users still using the free version received this rule after […]

More info:

https://www.wordfence.com/blog/2020/07/high-severity-vulnerability-patched-in-tc-custom-javascript/

Identificadores estándar

Propiedad Valor
CVE CVE-2020-14063.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2020-07-23

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT