Cross-Site Scripting Vulnerability in Wordfence Plugin for WordPress
CVE-2019-9669
6.1MEDIUM
Summary
The Wordfence plugin version 7.2.3 for WordPress is reported to contain a cross-site scripting (XSS) vulnerability, which can be exploited via a unique attack vector. It is important to note that this issue has been contested in the context of the Wordfence plugin due to the nature of its firewall rules. The rules are maintained externally on vendor servers and do not include versioning, making them separate from the plugin's core functionality. As such, bypassing these rules does not expose the WordPress site to traditional vulnerabilities.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved