← Back

CVE-2020-4049

nvd nist
Published: Jun 12, 2020Modified: Jun 17, 2026

JSON object

Loading...
2.4
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Exploitability: 0.9 / Impact: 1.4
Source: NVD

Description

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).

Affected (23)

1 product
Wordpress
1 product
Fedora
1 product
Debian Linux
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Wordpress
From 3.7 to 3.7.34
From 3.8 to 3.8.34
From 3.9 to 3.9.32
From 4.0 to 4.0.31
From 4.1 to 4.1.31
From 4.2 to 4.2.28
From 4.3 to 4.3.24
From 4.4 to 4.4.23
From 4.5 to 4.5.22
From 4.6 to 4.6.19
From 4.7 to 4.7.18
From 4.8 to 4.8.14
From 4.9 to 4.9.15
From 5.0 to 5.0.10
From 5.1 to 5.1.6
From 5.2 to 5.2.7
From 5.3.0 to 5.3.4
From 5.4 to 5.4.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0

References (16)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.