CVE-2020-4049

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
Basic XSS
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
GitHub_MCNA
2.4 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
wordpresswordpress
3.7 ≤
𝑥
< 3.7.34
wordpresswordpress
3.8 ≤
𝑥
< 3.8.34
wordpresswordpress
3.9 ≤
𝑥
< 3.9.32
wordpresswordpress
4.0 ≤
𝑥
< 4.0.31
wordpresswordpress
4.1 ≤
𝑥
< 4.1.31
wordpresswordpress
4.2 ≤
𝑥
< 4.2.28
wordpresswordpress
4.3 ≤
𝑥
< 4.3.24
wordpresswordpress
4.4 ≤
𝑥
< 4.4.23
wordpresswordpress
4.5 ≤
𝑥
< 4.5.22
wordpresswordpress
4.6 ≤
𝑥
< 4.6.19
wordpresswordpress
4.7 ≤
𝑥
< 4.7.18
wordpresswordpress
4.8 ≤
𝑥
< 4.8.14
wordpresswordpress
4.9 ≤
𝑥
< 4.9.15
wordpresswordpress
5.0 ≤
𝑥
< 5.0.10
wordpresswordpress
5.1 ≤
𝑥
< 5.1.6
wordpresswordpress
5.2 ≤
𝑥
< 5.2.7
wordpresswordpress
5.3.0 ≤
𝑥
< 5.3.4
wordpresswordpress
5.4 ≤
𝑥
< 5.4.2
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wordpress
bullseye (security)
5.7.11+dfsg1-0+deb11u1
fixed
bullseye
5.7.11+dfsg1-0+deb11u1
fixed
bookworm
6.1.6+dfsg1-0+deb12u1
fixed
bookworm (security)
6.1.6+dfsg1-0+deb12u1
fixed
sid
6.6.1+dfsg1-1
fixed
trixie
6.6.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wordpress
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
eoan
ignored
bionic
needs-triage
xenial
needs-triage
trusty
dne