CVE-2019-16250: High severity ocean extra vulnerability
Published Sep 11, 2019
·Updated
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
Affected Software
1 affected component
Oceanwp Ocean Extra WordPress<=1.5.8
Event History
Sep 11, 2019
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16250?
CVE-2019-16250 is a vulnerability in the Ocean Extra plugin for WordPress that allows unauthenticated options changes and injection of CSS token sequences.
2
How severe is CVE-2019-16250?
CVE-2019-16250 has a severity score of 7.5 (high).
3
How can I fix CVE-2019-16250?
To fix CVE-2019-16250, update the Ocean Extra plugin to version 1.5.9 or later.
4
What is the affected software of CVE-2019-16250?
The affected software of CVE-2019-16250 is the Ocean Extra plugin for WordPress up to version 1.5.8.
5
What is the CWE for CVE-2019-16250?
The CWE for CVE-2019-16250 is CWE-287 (Improper Authentication).