cleantalk
Vulnerabilities and Security Researches

Woody code snippets – Insert Header Footer Code, AdSense Ads, CVE-2019-15858

CVE, Research URL

CVE-2019-15858

Published on
Sep 03, 2019
Research Description
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
Affected versions
max 2.2.5.
Status
vulnerable