CVE-2020-12054

Detects 'Cross-Site Scripting (XSS)' vulnerability in Catch Breadcrumb plugin for WordPress affects v. before 1.5.4.


The Catch Breadcrumb plugin for WordPress is a popular tool used to create breadcrumb navigation on websites. This feature helps users to know where they are within a website, and makes it easier for them to navigate. The plugin also offers customizable settings, so that website owners can adjust the appearance of the breadcrumb navigation to match their website's style and layout. Catch Breadcrumb is widely used across various websites and has been downloaded more than 60,000 times.

However, the plugin was found to have a vulnerability code named CVE-2020-12054, which allows for Reflected XSS attacks through the "s" parameter in a search query. This means that an attacker can execute malicious scripts on a website by crafting a specially-crafted search query containing the XSS payload. This can cause various problems, such as stealing user data, installing malware, or even taking control of the website. This vulnerability can pose a significant risk to website owners and their users, making it important to take action to protect against it.

When exploited, this vulnerability can allow attackers to execute harmful scripts that can steal sensitive information, install malware, or take over the website. This can result in severe consequences, such as privacy violations, financial losses, and reputational damage to the website owner. As such, website owners must address this vulnerability as soon as possible to avoid any adverse consequences.

When exploited, this vulnerability can allow attackers to execute harmful scripts that can steal sensitive information, install malware, or take over the website. This can result in severe consequences, such as privacy violations, financial losses, and reputational damage to the website owner. As such, website owners must address this vulnerability as soon as possible to avoid any adverse consequences.



