Tag
#wordpress
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.