CVE-2019-15647: Code Injection
Published Aug 27, 2019
·Updated
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulkactionlistener remote code execution.
Affected Software
1 affected component
Groundhogg Groundhogg WordPress<1.3.5
Event History
Aug 27, 2019
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-15647.
2
What is the severity level of CVE-2019-15647?
The severity level of CVE-2019-15647 is high.
3
How does CVE-2019-15647 affect the Groundhogg plugin for WordPress?
CVE-2019-15647 allows remote code execution and affects the Groundhogg plugin for WordPress versions up to 1.3.5.
4
How can I fix CVE-2019-15647?
To fix CVE-2019-15647, update the Groundhogg plugin to version 1.3.5 or later.
5
Where can I find more information about CVE-2019-15647?
You can find more information about CVE-2019-15647 at the following references: [link1], [link2], [link3].