Junglewise Threat Intelligence

CVE-2020-37235: ThemeFTC Wibar Theme stored XSS in Brand component

CVE-2020-37235 · Severity: medium · CVSS 6.4 · Published 2026-05-16

Executive brief

Wibar is a professional WordPress theme used for e-commerce websites. A security flaw in its 'Brand' management feature allows users with basic posting privileges to inject malicious scripts into the site. When other visitors or administrators view the affected brand pages, these scripts could steal session information or redirect users to malicious websites.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Wibar WordPress theme version 1.1.8 and below. The flaw is located in the Brand component's 'Logo URL' input field (ftc_brand_url), which fails to properly sanitize user-supplied input. Authenticated attackers with roles as low as Contributor or Author can inject base64-encoded JavaScript payloads into this field. When a user subsequently visits the generated brand page, the malicious script executes within the context of their browser session. This can lead to unauthorized actions, session hijacking, or defacement of the affected pages.

Affected products

  • ThemeFTC Wibar Theme 1.1.8 and earlier

Timeline

  • 2020-11-27: disclosed: Initial exploit published on Exploit-DB
  • 2026-05-16: advisory: CVE published and NVD record created

References