CVE-2020-25380: Recall-Products Project Recall-Products
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that will be stored and executed.
Affected products
- Recall-Products Project Recall-Products: version 0.8 only
Published 2020-09-14. Last modified 2026-06-17.