PT-2019-11473 · Webappick+1 · Webappick Woocommerce Product Feed+1

Published

2019-07-23

·

Updated

2023-02-28

·

CVE-2019-1010124

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WebAppick WooCommerce Product Feed versions 2.2.18 and earlier
Description: The issue allows for Cross Site Scripting (XSS) which can lead to Remote Code Execution (RCE) via editing theme files in WordPress. This is possible when an administrator is logged in. The vulnerable component is located in the admin/partials/woo-feed-manage-list.php file at line 63.
Recommendations: For WebAppick WooCommerce Product Feed versions 2.2.18 and earlier, update to a version later than 2.2.18 to resolve the issue.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-1010124

Affected Products

Webappick Woocommerce Product Feed
Wordpress