First published: Mon Oct 07 2019(Updated: )
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Etoilewebdesign Ultimate Faq | <=1.8.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-17232.
The title of this vulnerability is 'Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.'
The affected software for this vulnerability is Etoilewebdesign Ultimate Faq plugin for WordPress version 1.8.24 and below.
The severity of CVE-2019-17232 is high with a CVSS score of 7.5.
To fix the CVE-2019-17232 vulnerability, update the ultimate-faqs plugin to version 1.8.25 or later.