Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2015-10114: V1.4.2 - Security Fix for _query_arg vulnerability. · wp-plugins/woosidebars@1ac6d6a

A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to open redirect. The attack may be launched remotely. Upgrading to version 1.4.2 is able to address this issue. The patch is identified as 1ac6d6ac26e185673f95fc1ccc56a392169ba601. It is recommended to upgrade the affected component. VDB-230654 is the identifier assigned to this vulnerability.

CVE
#xss#vulnerability#git#wordpress#php

Expand Up

@@ -2,8 +2,8 @@

Contributors: woothemes, mattyza

Tags: widgets, sidebars, widget-areas

Requires at least: 3.3

Tested up to: 4.1.0

Stable tag: 1.4.1

Tested up to: 4.1.1

Stable tag: 1.4.2

License: GPLv3 or later

License URI: http://www.gnu.org/licenses/gpl-3.0.html

Expand Down Expand Up

@@ -71,6 +71,9 @@ Looking to contribute code to this plugin? [Fork the repository over at GitHub](

== Upgrade Notice ==

= 1.4.2 =

Security Fix for XSS vulnerability

= 1.4.1 =

Fixes an error notice on the homepage, caused by the tag check logic.

Expand All

@@ -95,6 +98,10 @@ Moved to WordPress.org. Woo! Added scope to methods and properties where missing

== Changelog ==

= 1.4.2 =

* 2015-04-22

* Security Fix for remove_query_arg vulnerability

= 1.4.1 =

* 2015-02-17

Fixes an error notice on the homepage, caused by the tag check logic.

Expand Down

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907