vulnerability
WordPress Plugin: accessally: CVE-2020-36875: Improper Control of Generation of Code ('Code Injection')
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | Jan 21, 2020 | Jan 15, 2026 | Jan 15, 2026 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Jan 21, 2020
Added
Jan 15, 2026
Modified
Jan 15, 2026
Description
The AccessAlly plugin for WordPress is vulnerable to Arbitrary Code Execution in versions before 3.3.2 via the login_error function. This allows unauthenticated attackers to execute code on the server.
Solution
accessally-plugin-cve-2020-36875
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.