Metrics
Affected Vendors & Products
Mon, 18 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 17 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress buddypress Cover Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress buddypress Cover Wordpress wordpress |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onload that execute when administrators or privileged users preview or view the affected page content, enabling session hijacking and persistent phishing attacks. | |
| Title | WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting | |
| First Time appeared |
Boonebgorges
Boonebgorges buddypress Docs |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:boonebgorges:buddypress_docs:6.2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Boonebgorges
Boonebgorges buddypress Docs |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-24T01:36:56.209Z
Reserved: 2026-05-15T14:10:27.851Z
Link: CVE-2020-37233
Updated: 2026-05-18T18:10:52.472Z
Status : Deferred
Published: 2026-05-16T16:16:19.310
Modified: 2026-05-18T17:05:46.240
Link: CVE-2020-37233
No data.
OpenCVE Enrichment
Updated: 2026-05-17T18:45:07Z