Lucene search

K
cvelistMitreCVELIST:CVE-2019-20041
HistoryDec 27, 2019 - 7:14 a.m.

CVE-2019-20041

2019-12-2707:14:52
mitre
www.cve.org
5

AI Score

9.3

Confidence

High

EPSS

0.009

Percentile

82.5%

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

AI Score

9.3

Confidence

High

EPSS

0.009

Percentile

82.5%