PT-2019-13885 · Woocommerce · Woocommerce Product Add-Ons

CVE-2019-14948

·

Published

2019-08-12

·

Updated

2023-02-24

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions woocommerce-product-addon plugin version prior to 18.4
Description The issue allows for XSS via an import of a new meta data structure.
Recommendations For versions prior to 18.4, update to version 18.4 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14948

Affected Products

Woocommerce Product Add-Ons