widget-settings-importexport Plugin (WordPress) Warning
2755Warning Date
Severity Level
Warning Number
Target Sector
16 April, 2020
● High
2020-1146
All
Description:
WordPress has released a warning to address a vulnerability in the following product:
- widget-settings-importexport
Threats:
Attacker could exploit the vulnerability by doing the following:
- Cross-site scripting (XSS) attack
Best practice and Recommendations:
The CERT team encourages users to deactivate and remove the widget-settings-importexport plugin if it is installed on your site.