CVE-2020-13642
28.05.2020, 04:15
An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.
Vendor | Product | Version |
---|---|---|
siteorigin | page_builder | 𝑥 < 2.10.16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References