Security Advisory

CVE-2020-28650

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-11-16 02:49:50
Last updated 2024-08-04 16:40:59
Assigner mitre
State PUBLISHED

Description

The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.