PT-2019-11473 · Webappick+1 · Webappick Woocommerce Product Feed+1
Published
2019-07-23
·
Updated
2023-02-28
·
CVE-2019-1010124
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WebAppick WooCommerce Product Feed versions 2.2.18 and earlier
Description:
The issue allows for Cross Site Scripting (XSS) which can lead to Remote Code Execution (RCE) via editing theme files in WordPress. This is possible when an administrator is logged in. The vulnerable component is located in the
admin/partials/woo-feed-manage-list.php file at line 63.Recommendations:
For WebAppick WooCommerce Product Feed versions 2.2.18 and earlier, update to a version later than 2.2.18 to resolve the issue.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webappick Woocommerce Product Feed
Wordpress