First published: Thu Jul 23 2020(Updated: )
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Subscriptions | <2.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18834 is a vulnerability that allows remote attackers to execute arbitrary JavaScript in the WooCommerce Subscriptions plugin before version 2.6.3 for WordPress.
CVE-2019-18834 works by mishandling Billing Details in the WCS_Admin_Post_Types class of the WooCommerce Subscriptions plugin, which allows the execution of arbitrary JavaScript.
The severity of CVE-2019-18834 is medium with a CVSS score of 6.1.
The WooCommerce Subscriptions plugin before version 2.6.3 for WordPress is affected by CVE-2019-18834.
To fix CVE-2019-18834, update the WooCommerce Subscriptions plugin to version 2.6.3 or above.