S4E just found a medium-severity finding from asset blacklist checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-15858 Scanner

CVE-2019-15858 scanner - Cross-Site Scripting (XSS) vulnerability in Woody ad snippets plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-15858
8.8
CVSS

admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Woody ad snippets is a popular WordPress plugin that allows website owners to easily create and manage ad campaigns on their sites. This plugin provides a user-friendly interface and a variety of customization options to make the ad creation process as simple as possible. With its intuitive features, this plugin has become a must-have for website owners who want to boost their revenue by displaying ads on their site.

CVE-2019-15858 is a recently discovered vulnerability in the Woody ad snippets plugin. This vulnerability allows attackers to inject malicious code into the plugin's import options, which can lead to the execution of remote code. In simpler terms, this means that an attacker can exploit this vulnerability to inject harmful code into a website's ad campaigns, steal sensitive information, or even take control of the entire website.

If this vulnerability is exploited, the consequences can be severe for website owners. Hackers can use the vulnerability to steal sensitive information, such as user data and financial information, or to carry out other malicious activities, such as installing malware or stealing login credentials. This can result in significant financial losses, damage to the website's reputation, and in some cases, even legal action.

In conclusion, the Woody ad snippets plugin is a popular tool for website owners who want to monetize their site through ad campaigns. However, a recently discovered vulnerability (CVE-2019-15858) can potentially open up avenues for hackers to exploit the plugin. To mitigate the risk, website owners need to take adequate precautions, including regular vulnerability scanning, keeping plugins up to date, and implementing strict access controls. Thanks to the advanced features of S4E, website owners can easily and quickly learn about vulnerabilities in their digital assets and take appropriate action to ensure the safety of their sites.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take a number of simple precautions, including:

  • Keep all plugins, including Woody ad snippets, up to date with the latest security patches and upgrades.
  • Regularly scan the website for vulnerabilities and malware using a reputable security platform, like S4E.
  • Use strong and unique passwords for all website accounts and change them regularly.
  • Disable any unnecessary features or functionality in the Woody ad snippets plugin that may increase the risk of exploitation.
  • Implement strict access controls to limit who can access and modify the website's ad campaigns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.