Medium severity6.1NVD Advisory· Published Jul 23, 2020· Updated Jun 17, 2026
CVE-2019-18834
CVE-2019-18834
Description
Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Types in class-wcs-admin-post-types.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/WooCommerce Subscriptions plugindescription
- Range: <2.6.3
Patches
Vulnerability mechanics
References
3- www.precursorsecurity.com/blog/woocommerce-subscriptions-persistent-xss-cve-2019-18834nvdExploitThird Party Advisory
- woocommerce.com/products/woocommerce-subscriptions/nvdProductVendor Advisory
- www.precursorsecurity.com/blognvdThird Party Advisory
News mentions
0No linked articles in our index yet.