Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-36722


The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.


Published

2023-06-07T02:15:12.357

Last Modified

2024-11-21T05:30:09.710

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application visualcomposer visual_composer_website_builder ≤ 26.0 Yes

References