VYPR
Medium severity6.1NVD Advisory· Published Feb 28, 2022· Updated Jun 17, 2026

CVE-2020-36510

CVE-2020-36510

Description

The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:codetipi:15zine:*:*:*:*:*:wordpress:*:*
    Range: <3.3.0
  • WordPress/15Zine themedescription
  • WordPress/15Zinellm-fuzzy
    Range: <3.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.