Security Advisory

CVE-2019-15858

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-09-03 06:14:03
Last updated 2024-08-05 01:03:32
Assigner mitre
State PUBLISHED

Description

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.