CVE Feed

    Dashboard / CVE / CVE-2019-9669

    CVE-2019-9669

    The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as the firewall rules are not maintained as part of the Wordfence software but rather it is a set of rules hosted on vendor servers and pushed to the plugin with no versioning associated. Bypassing a WAF rule doesn't make a WordPress site vulnerable (speaking in terms of software vulnerabilities)

    Published:Apr 25, 2019
    Last Modified:Nov 21, 2024
    EPS:Apr 25, 2019
    EPSS Score:0.00216
    CVSS Score:6.1

    Affected Products

    Vendor
    Wordfence
    Product
    Wordfence

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High