Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2015-9410: XSS Vulnerability in Blubrry PowerPress Podcasting plugin Version 6.0.4 · Issue #7 · cybersecurityworks/Disclosed

The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.

CVE
#xss#vulnerability#wordpress#php
CVE-2016-10961: Summer of Pwnage! July 1-29, Amsterdam.

The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.

CVE-2016-10954: Unrestricted Upload/RCE in Neosense theme 1.7

The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

CVE-2016-10953: Headway 3.8.9 Patches Potential XSS Vulnerability

The Headway theme before 3.8.9 for WordPress has XSS via the license key field.

CVE-2016-10945: PageLines Platform 1.1.4 CSRF vulnerability | Klikki

The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.

CVE-2019-16223: WordPress 5.2.3 Security and Maintenance Release

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVE-2018-21012: CF7 Invisible reCAPTCHA

The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.

CVE-2019-16120: Event Tickets and Registration

CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.

CVE-2019-16119

SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.

CVE-2019-16118

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.