PT-2019-13841 · Woocommerce · Mq-Woocommerce-Products-Price-Bulk-Edit

Published

2019-08-09

·

Updated

2023-03-03

·

CVE-2019-14796

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mq-woocommerce-products-price-bulk-edit plugin version 2.0
Description The issue allows for XSS via the "wp-admin/admin-ajax.php?action=update options" API endpoint, specifically through the show products page limit parameter.
Recommendations For mq-woocommerce-products-price-bulk-edit plugin version 2.0, avoid using the show products page limit parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-14796

Affected Products

Mq-Woocommerce-Products-Price-Bulk-Edit