Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-13 16:16
Updated : 2026-06-17 03:17
NVD link : CVE-2020-37225
Mitre link : CVE-2020-37225
CVE.ORG link : CVE-2020-37225
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
