Search Results (18007 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-10023 1 Editorial Calendar Project 1 Editorial Calendar 2024-11-21 6.3 Medium
A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched remotely. Upgrading to version 2.7 is able to address this issue. The patch is named a9277f13781187daee760b4dfd052b1b68e101cc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-225151.
CVE-2013-10022 1 Bestwebsoft 1 Contact Form 2024-11-21 3.5 Low
A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 3.52 is able to address this issue. The patch is identified as 642ef1dc1751ab6642ce981fe126325bb574f898. It is recommended to upgrade the affected component. VDB-225002 is the identifier assigned to this vulnerability.
CVE-2013-10021 1 Wordpress 1 Debug Bar 2024-11-21 3.5 Low
A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function render of the file panels/class-debug-bar-queries.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 0.8.1 is able to address this issue. The patch is named 0842af8f8a556bc3e39b9ef758173b0a8a9ccbfc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222739.
CVE-2013-10020 1 A-forms Project 1 A-forms 2024-11-21 3.5 Low
A vulnerability, which was classified as problematic, was found in MMDeveloper A Forms Plugin up to 1.4.2 on WordPress. This affects an unknown part of the file a-forms.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The identifier of the patch is 3e693197bd69b7173cc16d8d2e0a7d501a2a0b06. It is recommended to upgrade the affected component. The identifier VDB-222609 was assigned to this vulnerability.
CVE-2013-0291 1 Imagely 1 Nextgen Gallery 2024-11-21 7.5 High
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
CVE-2013-0286 1 Pinboard Project 1 Pinboard 2024-11-21 5.4 Medium
Pinboard 1.0.6 theme for Wordpress has XSS.
CVE-2012-6719 1 Sharebar Project 1 Sharebar 2024-11-21 N/A
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
CVE-2012-6718 1 Sharebar Project 1 Sharebar 2024-11-21 N/A
The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.
CVE-2012-6717 1 Redirection 1 Redirection 2024-11-21 N/A
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.
CVE-2012-6716 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
CVE-2012-6715 1 Formbuilder Project 1 Formbuilder 2024-11-21 N/A
The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.
CVE-2012-6714 1 Count Per Day Project 1 Count Per Day 2024-11-21 N/A
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
CVE-2012-6713 1 Wp-jobmanager 1 Job Manager 2024-11-21 N/A
The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.
CVE-2012-6652 1 Page Flip Book Project 1 Page Flip Book 2024-11-21 N/A
Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.
CVE-2012-6649 1 Devfarm 1 Wp Gpx Maps 2024-11-21 9.8 Critical
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
CVE-2012-4919 1 Gallery Project 1 Gallery 2024-11-21 9.8 Critical
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
CVE-2012-10016 1 Halulu 1 Simple-download-button-shortcode 2024-11-21 4.3 Medium
A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPress. Affected is an unknown function of the file simple-download-button_dl.php of the component Download Handler. The manipulation of the argument file leads to information disclosure. It is possible to launch the attack remotely. Upgrading to version 1.1 is able to address this issue. The patch is identified as e648a8706818297cf02a665ae0bae1c069dea5f1. It is recommended to upgrade the affected component. VDB-242190 is the identifier assigned to this vulnerability.
CVE-2012-10015 1 Bestwebsoft 1 Twitter 2024-11-21 4.3 Medium
A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file twitter.php of the component Settings Page. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 2.15 is able to address this issue. The patch is identified as a6d4659cbb2cbf18ccb0fb43549d5113d74e0146. It is recommended to upgrade the affected component. VDB-230154 is the identifier assigned to this vulnerability.
CVE-2012-10014 1 Kau-boys 1 Backend Localization 2024-11-21 3.5 Low
A vulnerability classified as problematic has been found in Kau-Boy Backend Localization Plugin 2.0 on WordPress. Affected is the function backend_localization_admin_settings/backend_localization_save_setting/backend_localization_login_form/localize_backend of the file backend_localization.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.1 is able to address this issue. The name of the patch is 36f457ee16dd114e510fd91a3ea9fbb3c1f87184. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227232.
CVE-2012-10013 1 Kau-boys 1 Backend Localization 2024-11-21 3.5 Low
A vulnerability was found in Kau-Boy Backend Localization Plugin up to 1.6.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the file backend_localization.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is named 43dc96defd7944da12ff116476a6890acd7dd24b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227231.