Unknown · CVSS Not scored
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
Published Oct 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=addthis_social_widget pubid parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of the log file if the error message is "Unhandled exception in Dalvik VM," "Application not responding ANR event," or "Crash on an application's native code." The Samsung ID is SVE-2015-2885 (October 2015).
Published Apr 10, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
Published Aug 30, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.
Published Oct 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Conditional Success Redirects extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
Published Jan 4, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
Published Nov 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) CSV Manager extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.
Published Sep 26, 2019 · Updated Aug 6, 2024