Medium severity5.4NVD Advisory· Published Aug 12, 2019· Updated Jun 17, 2026
CVE-2019-14948
CVE-2019-14948
Description
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/woocommerce-product-addon plugindescription
- cpe:2.3:a:najeebmedia:ppom_for_woocommerce:*:*:*:*:*:wordpress:*:*Range: <18.4
- Range: <18.4
Patches
Vulnerability mechanics
References
3- www.pluginvulnerabilities.com/2019/08/08/this-authenticated-persistent-xss-vulnerability-might-be-what-hackers-are-targeting-ppom-for-woocommerce-for/nvdExploitThird Party Advisory
- wpvulndb.com/vulnerabilities/9502nvdThird Party Advisory
- wordpress.org/plugins/woocommerce-product-addon/nvdRelease Notes
News mentions
0No linked articles in our index yet.