Unknown · CVSS Not scored
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
Published Feb 24, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
Published Oct 10, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The relevant plugin before 1.0.8 for WordPress has XSS.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
Published Oct 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.
Published Oct 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Published Oct 23, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/captcha/index.php/ PATH_SELF.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php account_id parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
Published Oct 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Postmatic plugin before 1.4.6 for WordPress has XSS.
Published Sep 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.
Published Oct 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Published Oct 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
Published Sep 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.
Published Sep 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.
Published Sep 26, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.
Published Oct 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
Published Sep 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
Published Sep 25, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
Published Aug 28, 2019 · Updated Aug 6, 2024