CVE-2019-16289: XSS
Published Sep 13, 2019
·Updated
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winpitem parameter.
Affected Software
1 affected component
Webcraftic Woody Ad Snippets Wordpress<2.2.8
Event History
Sep 13, 2019
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16289?
CVE-2019-16289 has a severity rating that may lead to authenticated cross-site scripting (XSS) vulnerabilities.
2
How does CVE-2019-16289 exploit authenticated users?
CVE-2019-16289 exploits vulnerabilities through the winp_item parameter, allowing attackers with authenticated access to execute scripts.
3
How do I mitigate CVE-2019-16289?
Mitigating CVE-2019-16289 involves upgrading the Woody Ad Snippets plugin to version 2.2.8 or later.
4
What are the potential impacts of CVE-2019-16289 if exploited?
If exploited, CVE-2019-16289 can lead to unauthorized actions performed on behalf of users, which can compromise site integrity.
5
Who is affected by CVE-2019-16289?
CVE-2019-16289 affects users of the Woody Ad Snippets plugin versions prior to 2.2.8 on WordPress.