Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.
Published Apr 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
Published Jan 24, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.
Published Aug 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.
Published Apr 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web management interface on the WAN interface.
Published Nov 24, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
Published Feb 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
Published Sep 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) htaccess Editor extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
Published Jun 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
Published Oct 10, 2019 · Updated Aug 6, 2024