CVE Database
/

CVE-2020-36656

Back to search

CVE-2020-36656

Published: Feb 21, 2023

Modified: Apr 23, 2025

PUBLISHED

Description

The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.

VendorProductVersions

Unknown

Spectra

affected
0 - < 1.15.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now