CVE-2019-17239: XSS
Published Oct 7, 2019
·Updated
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
Affected Software
1 affected component
WPFactory Download Plugins And Themes From Dashboard Wordpress<=1.5.0
Event History
Oct 7, 2019
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
Description
Frequently Asked Questions
1
What is CVE-2019-17239?
CVE-2019-17239 is a vulnerability in the download-plugins-dashboard plugin for WordPress, allowing for multiple unauthenticated stored XSS issues.
2
How severe is CVE-2019-17239?
CVE-2019-17239 has a severity level of medium with a CVSS score of 6.1.
3
How can I fix the CVE-2019-17239 vulnerability?
To fix the CVE-2019-17239 vulnerability, update the download-plugins-dashboard plugin to version 1.5.1 or later.
4
Where can I find more information about CVE-2019-17239?
You can find more information about CVE-2019-17239 on the WordPress plugin page (https://wordpress.org/plugins/download-plugins-dashboard/#developers) and the WPVulnDB page (https://wpvulndb.com/vulnerabilities/9896).