CVE-2020-28650

Publication date

2020-11-16 02:49:50

Family

mitre

State

PUBLISHED

Description

The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.