CVE-2019-14948: XSS
Published Aug 12, 2019
·Updated
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
Affected Software
1 affected component
Najeebmedia Ppom For Woocommerce Wordpress<18.4
Event History
Aug 12, 2019
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14948?
The severity of CVE-2019-14948 is medium with a severity value of 5.4.
2
How does CVE-2019-14948 affect the woocommerce-product-addon plugin?
CVE-2019-14948 affects the woocommerce-product-addon plugin version up to and exclusive of 18.4 for WordPress.
3
What is the description of CVE-2019-14948?
CVE-2019-14948 is a cross-site scripting (XSS) vulnerability in the woocommerce-product-addon plugin for WordPress, enabled through the import of a new meta data structure.
4
How can I fix CVE-2019-14948?
To fix CVE-2019-14948, update the woocommerce-product-addon plugin to version 18.4 or later.
5
What is the CWE ID of CVE-2019-14948?
The CWE ID of CVE-2019-14948 is 79.