CVE-2019-14796
Woocommerce Products Price Bulk Edit <= 2.0 - Cross-Site Scripting via show_products_page_limit parameter
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.
El plugin mq-wooWordPresscommerce-products-price-bulk-edit (también se conoce como Woocommerce Products Price Bulk Edit) versión 2.0 para WordPress, permite un ataque de tipo XSS por medio del parámetro wp-admin/admin-ajax.php?action=update_options show_products_page_limit.
The Woocommerce Products Price Bulk Edit plugin for WordPress is vulnerable to Cross-Site Scripting via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-17 CVE Published
- 2019-08-09 CVE Reserved
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/#developers | Release Notes | |
https://wpvulndb.com/vulnerabilities/9515 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mq-woocommerce-products-price-bulk-edit Project Search vendor "Mq-woocommerce-products-price-bulk-edit Project" | Mq-woocommerce-products-price-bulk-edit Search vendor "Mq-woocommerce-products-price-bulk-edit Project" for product "Mq-woocommerce-products-price-bulk-edit" | 2.0 Search vendor "Mq-woocommerce-products-price-bulk-edit Project" for product "Mq-woocommerce-products-price-bulk-edit" and version "2.0" | wordpress |
Affected
|