5.4
CVSSv3

CVE-2019-1010124

Published: 23/07/2019 Updated: 28/02/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

WebAppick WooCommerce Product Feed 2.2.18 and previous versions is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webappick woocommerce product feed

Exploits

# Exploit Title: WordPress Plugin WooCommerce Product Feed <= 2218 - Cross-Site Scripting # Date: 30 August 2019 # Exploit Author: Damian Ebelties (zerodayslol/) # Vendor Homepage: wordpressorg/plugins/webappick-product-feed-for-woocommerce/ # Version: <= 2218 # Tested on: Ubuntu 18041 # CVE: CVE-2019-1010124 The Word ...
WordPress WooCommerce Product Feed plugin versions 2218 and below suffer from a cross site scripting vulnerability ...