CVE-2019-15771: Medium severity wpbakery page builder vulnerability
Published Aug 29, 2019
·Updated
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv AJAX action that allows modification of the siteurl setting.
Affected Software
1 affected component
Components For Wp Bakery Page Builder Project Components For Wp Bakery Page Builder<6.0
Event History
Aug 29, 2019
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15771?
CVE-2019-15771 is considered a high-severity vulnerability because it allows unauthorized attackers to modify the siteurl setting.
2
How do I fix CVE-2019-15771?
To fix CVE-2019-15771, update to version 6.0 or later of the nd-shortcodes plugin.
3
What does CVE-2019-15771 affect?
CVE-2019-15771 affects the nd-shortcodes plugin for WordPress prior to version 6.0.
4
Can CVE-2019-15771 be exploited remotely?
Yes, CVE-2019-15771 can be exploited remotely through an AJAX action available to unauthenticated users.
5
What are the potential consequences of CVE-2019-15771?
Exploitation of CVE-2019-15771 can lead to unauthorized changes in the site settings, affecting the site's integrity and security.