S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-12054 Scanner

CVE-2020-12054 scanner - Cross-Site Scripting (XSS) vulnerability in Catch Breadcrumb plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-12054
6.1
CVSS

The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Catch Breadcrumb plugin for WordPress is a popular tool used to create breadcrumb navigation on websites. This feature helps users to know where they are within a website, and makes it easier for them to navigate. The plugin also offers customizable settings, so that website owners can adjust the appearance of the breadcrumb navigation to match their website's style and layout. Catch Breadcrumb is widely used across various websites and has been downloaded more than 60,000 times.

However, the plugin was found to have a vulnerability code named CVE-2020-12054, which allows for Reflected XSS attacks through the "s" parameter in a search query. This means that an attacker can execute malicious scripts on a website by crafting a specially-crafted search query containing the XSS payload. This can cause various problems, such as stealing user data, installing malware, or even taking control of the website. This vulnerability can pose a significant risk to website owners and their users, making it important to take action to protect against it.

When exploited, this vulnerability can allow attackers to execute harmful scripts that can steal sensitive information, install malware, or take over the website. This can result in severe consequences, such as privacy violations, financial losses, and reputational damage to the website owner. As such, website owners must address this vulnerability as soon as possible to avoid any adverse consequences.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. With the platform's comprehensive scanning and reporting capabilities, website owners can identify potential vulnerabilities and take swift action to address them. The platform also provides actionable insights and tips to help website owners improve their security posture and protect their digital assets effectively. So, website owners can rely on this platform to enhance their website security and prevent vulnerabilities like CVE-2020-12054.

 

REFERENCES

Solution Advice

To protect against the CVE-2020-12054 vulnerability, website owners can take various precautions. These include:

  • Updating the Catch Breadcrumb plugin to the latest version that has patched this vulnerability.
  • Using a Web Application Firewall (WAF) to filter out malicious requests and payloads.
  • Enabling Content Security Policy (CSP) on their website, which can prevent unauthorized execution of scripts.
  • Being cautious while browsing websites, especially when submitting sensitive information.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-12054 scanner - Cross-Site Scripting (XSS) vulnerability in Catch Breadcrumb plugin for WordPress | S4E