Vulnerability Description
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fastvelocity | Minify | < 2.7.7 |
Related Weaknesses (CWE)
References
- https://wpvulndb.com/vulnerabilities/9914Third Party Advisory
- https://www.wordfence.com/blog/2019/10/medium-severity-vulnerability-patched-in-ExploitThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9914Third Party Advisory
- https://www.wordfence.com/blog/2019/10/medium-severity-vulnerability-patched-in-ExploitThird Party Advisory
FAQ
What is CVE-2019-19983?
CVE-2019-19983 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs ...
How severe is CVE-2019-19983?
CVE-2019-19983 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19983?
Check the references section above for vendor advisories and patch information. Affected products include: Fastvelocity Minify.