CVE-2019-15816: XSS
The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via savesettingspage and other save functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15816?
CVE-2019-15816 is considered a high-severity vulnerability due to the potential for unauthorized options changes in the WordPress wp-private-content-plus plugin.
How do I fix CVE-2019-15816?
To fix CVE-2019-15816, update the wp-private-content-plus plugin to version 2.0 or later.
What are the potential impacts of CVE-2019-15816?
The impacts of CVE-2019-15816 include unauthorized changes to plugin settings and possible compromise of site functionality.
Who is affected by CVE-2019-15816?
Any WordPress site using the wp-private-content-plus plugin versions prior to 2.0 is affected by CVE-2019-15816.
What is wp-private-content-plus in relation to CVE-2019-15816?
The wp-private-content-plus plugin is a WordPress plugin vulnerable to CVE-2019-15816, which allows unauthenticated users to change settings.