VYPR
Medium severity5.8NVD Advisory· Published Apr 30, 2020· Updated Jun 17, 2026

CVE-2020-11025

CVE-2020-11025

Description

In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • WordPress/WordPressllm-fuzzy3 versions
    <5.4.1, <5.3.3, <5.2.6, <5.1.5, <5.0.9, <4.9.14, <4.7.17, <4.6.18, <4.5.21, <4.4.22, <4.3.23, <4.2.27, <4.1.30, <4.0.30, <3.9.31, <3.8.33, <3.7.33+ 2 more
    • (no CPE)range: <5.4.1, <5.3.3, <5.2.6, <5.1.5, <5.0.9, <4.9.14, <4.7.17, <4.6.18, <4.5.21, <4.4.22, <4.3.23, <4.2.27, <4.1.30, <4.0.30, <3.9.31, <3.8.33, <3.7.33
    • cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=4.7,<5.4.1
    • (no CPE)range: >= 5.4.0, < 5.4.1
  • osv-coords2 versions
    >= 4.7.0, < 5.4.1+ 1 more
    • (no CPE)range: >= 4.7.0, < 5.4.1
    • (no CPE)range: >= 4.7.0, < 5.4.1
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.