← Back to CVE List

CVE-2020-11508

Published: 2020-04-07T19:15Z
Last Modified: 2024-11-21T04:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt