Cross-Site Scripting Vulnerability in Wordfence Plugin for WordPress
CVE-2019-9669

6.1MEDIUM

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
25 April 2019

Summary

The Wordfence plugin version 7.2.3 for WordPress is reported to contain a cross-site scripting (XSS) vulnerability, which can be exploited via a unique attack vector. It is important to note that this issue has been contested in the context of the Wordfence plugin due to the nature of its firewall rules. The rules are maintained externally on vendor servers and do not include versioning, making them separate from the plugin's core functionality. As such, bypassing these rules does not expose the WordPress site to traditional vulnerabilities.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.