| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The google-document-embedder plugin before 2.6.1 for WordPress has XSS. |
| The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS. |
| The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. |
| The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. |
| The wp-database-backup plugin before 4.3.1 for WordPress has XSS. |
| The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. |
| The wp-database-backup plugin before 4.3.3 for WordPress has XSS. |
| The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. |
| The google-language-translator plugin before 5.0.06 for WordPress has XSS. |
| The contact-form-plugin plugin before 4.0.2 for WordPress has XSS. |
| The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages. |
| The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages. |
| The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues. |
| The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS. |
| The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body. |
| The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. |
| The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter. |
| The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. |
| The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. |
| WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind vulnerable website or to perform otherwise restricted actions and subsequently download files with the extension mp3, mp4a, wav and ogg from anywhere the web server application has read access to the system. WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files version 1.7.6 is vulnerable; prior versions may also be affected. |