CVE-2019-15858
HIGH 8.8EPSS 18.5%
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 18.46% chance of exploitation in the next 30 days, 97th percentile
- Nuclei
- high
- Published
- 2019-09-03
- Updated
- 2024-08-05
Proof-of-concept exploits (3)
- GeneralEG/CVE-2019-1585832★ · 2023-04-25
- ismail0x01/CVE-20190★ · 2025-04-23
- orangmuda/CVE-2019-158583★ · 2021-10-11