Vulnerability Description
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mq-Woocommerce-Products-Price-Bulk-Edit Project | Mq-Woocommerce-Products-Price-Bulk-Edit | 2.0 |
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/#developerRelease Notes
- https://wpvulndb.com/vulnerabilities/9515Third Party Advisory
- https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistenExploitThird Party Advisory
- https://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/#developerRelease Notes
- https://wpvulndb.com/vulnerabilities/9515Third Party Advisory
- https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistenExploitThird Party Advisory
FAQ
What is CVE-2019-14796?
CVE-2019-14796 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limi...
How severe is CVE-2019-14796?
CVE-2019-14796 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14796?
Check the references section above for vendor advisories and patch information. Affected products include: Mq-Woocommerce-Products-Price-Bulk-Edit Project Mq-Woocommerce-Products-Price-Bulk-Edit.