CVE-2020-37225 MEDIUM

CVE-2020-37225: Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting

Vendor Powie
Product WHOIS Domain Check
Weakness CWE-79 · XSS
Published May 13, 2026
Last update May 24, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php configuration page to execute JavaScript in the admin context and escalate privileges.

Key dates

02Disclosure timeline

May 13, 2026 CVE published
May 24, 2026 Record updated