The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/shapepress-dsgvo/#developers | Product Third Party Advisory |
https://wpvulndb.com/vulnerabilities/9850 | Third Party Advisory |
https://www.pluginvulnerabilities.com/2019/08/22/gdpr-plugins-for-wordpress-continue-to-be-insecure/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-08-29 12:15
Updated : 2024-02-28 17:08
NVD link : CVE-2019-15777
Mitre link : CVE-2019-15777
CVE.ORG link : CVE-2019-15777
JSON object : View
Products Affected
shapepress
- wp_dsgvo_tools
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')