CVE-2020-28034
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 1.7%
from disclosure to weapon
Published on NVDOct 31
VulnCheckOct 29
exploitation probability
1.7%top 23% of all CVEs
observed exploitation
yesVulnCheck
WordPress before 5.5.2 allows XSS associated with global variables.
Affected products
n/a · n/aReferences
https://lists.debian.org/debian-lts-announce/2020/11/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHVNK2WYAM3ZTCXTFSEIT56IKLVJHU3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VAVVYJKA2I6CRQUINECDPBGWMQDEG244/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUXVUAKL2HL4QYJEPHBNVQQWRMFMII2Y/https://wordpress.org/news/2020/10/wordpress-5-5-2-security-and-maintenance-release/https://www.debian.org/security/2020/dsa-4784