Tag
#wordpress
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
The Headway theme before 3.8.9 for WordPress has XSS via the license key field.
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.