CVE-2019-14819

Current Description

The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.

Basic Data

PublishedAugust 09, 2019
Last ModifiedAugust 20, 2019
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-79
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationSINGLE
CVSS 2 - Confidentiality ImpactNONE
CVSS 2 - Availability ImpactNONE
CVSS 2 - Base Score3.5
SeverityLOW
Exploitability Score6.8
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

CVSS 3 - Version3.0
CVSS 3 - Vector StringCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 3 - Attack VectorNETWORK
CVSS 3 - Attack ComplexityLOW
CVSS 3 - Privileges RequiredLOW
CVSS 3 - User InteractionREQUIRED
CVSS 3 - ScopeCHANGED
CVSS 3 - Confidentiality ImpactLOW
CVSS 3 - Integrity ImpactLOW
CVSS 3 - Availability ImpactNONE
CVSS 3 - Base Score5.4
CVSS 3 - Base SeverityMEDIUM
Exploitability Score2.3
Base SeverityMEDIUM

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationMq-woocommerce-products-price-bulk-edit ProjectMq-woocommerce-products-price-bulk-edit2.0****CVE-2007-2829**

Vulnerable Software List

VendorProductVersions
Mq-woocommerce-products-price-bulk-edit Project Mq-woocommerce-products-price-bulk-edit 2.0

References

NameSourceURLTags
https://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/#developershttps://wordpress.org/plugins/mq-woocommerce-products-price-bulk-edit/#developersMISCThird Party Advisory
https://wpvulndb.com/vulnerabilities/9515https://wpvulndb.com/vulnerabilities/9515MISC
https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistent-cross-site-scripting-xss-vulnerability-what-hackers-would-be-interested-in-woocommerce-products-price-bulk-edit-for/https://www.pluginvulnerabilities.com/2019/05/16/is-this-authenticated-persistent-cross-site-scriptiMISCExploit Third Party Advisory