Medium severity5.4NVD Advisory· Published Sep 13, 2019· Updated Jun 17, 2026
CVE-2019-16289
CVE-2019-16289
Description
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:webcraftic:woody_ad_snippets:*:*:*:*:*:wordpress:*:*Range: <2.2.8
Patches
Vulnerability mechanics
References
3- generaleg0x01.com/2019/09/13/xss-woody/nvdExploitThird Party Advisory
- wpvulndb.com/vulnerabilities/9880nvdThird Party Advisory
- wordpress.org/plugins/insert-php/nvdRelease Notes
News mentions
0No linked articles in our index yet.