First published: Tue Sep 03 2019(Updated: )
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Woody Ad Snippets | <2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15858 is considered a critical vulnerability due to its potential for unauthenticated remote code execution.
To fix CVE-2019-15858, update the Woody ad snippets plugin to version 2.2.5 or later.
CVE-2019-15858 affects versions of the Woody ad snippets plugin prior to 2.2.5 on WordPress websites.
CVE-2019-15858 is a vulnerability that allows unauthenticated options import, which can lead to cross-site scripting (XSS) attacks.
Any WordPress site using the Woody ad snippets plugin version before 2.2.5 is vulnerable to CVE-2019-15858.