Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2019-19306: ZOHO CRM Lead Magnet version 1.6.9.1 · Issue #16 · cybersecurityworks/Disclosed

The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

CVE
#xss#vulnerability#web#mac#java#wordpress#php#auth
CVE-2019-18854: Changeset 2185438 – WordPress Plugin Repository

A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.

CVE-2019-17670

WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.

CVE-2019-17675: Changeset 46477 – WordPress Trac

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

CVE-2016-10961: Summer of Pwnage! July 1-29, Amsterdam.

The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.

CVE-2016-10954: Unrestricted Upload/RCE in Neosense theme 1.7

The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

CVE-2016-10953: Headway 3.8.9 Patches Potential XSS Vulnerability

The Headway theme before 3.8.9 for WordPress has XSS via the license key field.

CVE-2016-10945: PageLines Platform 1.1.4 CSRF vulnerability | Klikki

The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.

CVE-2019-16223: WordPress 5.2.3 Security and Maintenance Release

WordPress before 5.2.3 allows XSS in post previews by authenticated users.