ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36853”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36853
Published
2025-10-18
CVSS:
7.2
ShadowTrackr CVSS:
1.7
Summary:
The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.