CVE-2020-12054
WordPress vulnerability analysis and mitigation

Overview

The Catch Breadcrumb WordPress plugin before version 1.5.4 contains a Reflected Cross-Site Scripting (XSS) vulnerability. The vulnerability was discovered on April 20, 2020, and was assigned CVE-2020-12054. The issue affects not only the plugin but also 16 themes by the same author when used in conjunction with the vulnerable plugin (CX Security, WPScan).

Technical details

The vulnerability allows for Reflected XSS attacks via the 's' parameter, which is used for search queries. The issue received a CVSS v3.1 base score of 6.1 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) (NVD).

Impact

If exploited, this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of other users' browsers who visit the affected search pages. This could lead to theft of sensitive information, session hijacking, or other malicious actions performed in the context of the affected user's session (WPScan).

Exploitability

The vulnerability is exploitable without authentication, requiring only that a user visits a specially crafted URL containing malicious JavaScript in the search parameter. A proof of concept exists demonstrating the exploitation through the search functionality of affected websites (CX Security).

Mitigation and workarounds

The vulnerability was patched in version 1.5.7 of the Catch Breadcrumb plugin. Website administrators should update to this version or later to protect against this vulnerability. Between April 23rd to 25th, 2020, various versions were released to add proper validation and sanitization of input (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81648CRITICAL10
  • cryptopayment-gateway
NoNoSep 13, 2026
CVE-2026-88793HIGH8.8
  • youram-youtube-embed
NoNoSep 13, 2026
CVE-2026-85129HIGH8.8
  • hoo-companion
NoNoSep 13, 2026
CVE-2026-88802HIGH7.5
  • mobile-events-manager
NoYesSep 13, 2026
CVE-2026-89050MEDIUM4.3
  • quick-adsense-reloaded
NoYesSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management