2019-09-13 17:15:11 2019-09-16 15:58:37

The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.

Vector

NETWORK

Complexity

MEDIUM

Authentication

SINGLE_INSTANCE

Confidentiality

NONE

Integrity

PARTIAL

Availability

NONE
Webcraftic Woody ad snippets - ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 1.0 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 1.1 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 1.2 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 1.3 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.0.1 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.0.2 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.0.4 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.0.6 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.2 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.3 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.4 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.5 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.6 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.7 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.9 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.1.91 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.2.1 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.2.2 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.2.4 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.2.5 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.2.6 ~~~wordpress~~ (not an official CPE) Webcraftic Woody ad snippets 2.2.7 ~~~wordpress~~ (not an official CPE)