CVE-2019-15858: XSS
Published Sep 3, 2019
·Updated
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
Affected Software
1 affected component
Webcraftic Woody Ad Snippets Wordpress<2.2.5
Event History
Sep 3, 2019
CVE Published
via MITRE·06:14 AM
Data Sourced
via MITRE·06:14 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15858?
CVE-2019-15858 is considered a critical vulnerability due to its potential for unauthenticated remote code execution.
2
How do I fix CVE-2019-15858?
To fix CVE-2019-15858, update the Woody ad snippets plugin to version 2.2.5 or later.
3
What systems are affected by CVE-2019-15858?
CVE-2019-15858 affects versions of the Woody ad snippets plugin prior to 2.2.5 on WordPress websites.
4
What type of vulnerability is CVE-2019-15858?
CVE-2019-15858 is a vulnerability that allows unauthenticated options import, which can lead to cross-site scripting (XSS) attacks.
5
Who is affected by CVE-2019-15858?
Any WordPress site using the Woody ad snippets plugin version before 2.2.5 is vulnerable to CVE-2019-15858.