Medium 6.4
2025-10-18< 2.20.02.27
CVE-2020-36854
Minimum safe version
2.21.06.29
Update to 2.21.06.29 or later to address 7 fixable vulnerabilities
CVE-2020-36854
Async JavaScript <= 2.19.07.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Async Javascript <= 2.20.12.09 - Authenticated (Admin+) Cross-Site Scripting
Async Javascript < 2.20.02.27 - Subscriber+ Stored XSS via Plugin Settings Change
Async JavaScript < 2.21.06.29 - Authenticated (admin+) Stored XSS
WordPress Async JavaScript plugin <= 2.19.07.14 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Async JavaScript plugin <= 2.20.12.09 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability