Cross-Site Scripting Vulnerability in Wordfence Plugin for WordPress
CVE-2019-9669
6.1MEDIUM
What is CVE-2019-9669?
The Wordfence plugin version 7.2.3 for WordPress is reported to contain a cross-site scripting (XSS) vulnerability, which can be exploited via a unique attack vector. It is important to note that this issue has been contested in the context of the Wordfence plugin due to the nature of its firewall rules. The rules are maintained externally on vendor servers and do not include versioning, making them separate from the plugin's core functionality. As such, bypassing these rules does not expose the WordPress site to traditional vulnerabilities.