---
id: CVE-2020-37235
title: >-
  WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting
  vulnerability in the Brand component that allows authenticated users to inject
  malicious scripts by manipulating the Logo URL parameter
summary: >-
  WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting
  vulnerability in the Brand component that allows authenticated users to inject
  malicious scripts by manipulating the Logo URL parameter. Attackers with
  editor, administra…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37235'
references:
  - url: 'http://demo.themeftc.com/wibar'
    label: disclosure@vulncheck.com
  - url: >-
      https://themeforest.net/item/wibar-responsive-woocommerce-wordpress-theme/20994798
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/49107'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-theme-wibar-stored-cross-site-scripting-via-brand-component
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00243
epssPercentile: 0.13896
ingestedAt: '2026-09-29T10:31:36.285Z'
---

## Overview

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encoded script payloads through the ftc_brand_url input field to execute arbitrary JavaScript when users visit the brand page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
