Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2018-21012: CF7 Invisible reCAPTCHA

The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.

CVE
#xss#vulnerability#web#google#js#git#java#wordpress#sap
CVE-2019-16120: Event Tickets and Registration

CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.

CVE-2019-16119

SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.

CVE-2019-16118

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.

CVE-2019-16117

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.

CVE-2019-15838: Custom 404 Pro

The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.

CVE-2018-21004

The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.

CVE-2019-15317: WordPress Plugin Give - Stored XSS for Donors

The give plugin before 2.4.7 for WordPress has XSS via a donor name.