Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

WordPress Page Builder KingComposer 2.9.6 Cross Site Scripting

WordPress Page Builder KingComposer plugin version 2.9.6 suffers from a cross site scripting vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#wordpress#php#perl#auth#ruby#firefox
WordPress Page Builder KingComposer 2.8.1 Cross Site Scripting

WordPress Page Builder KingComposer plugin version 2.8.1 suffers from a cross site scripting vulnerability.

WordPress Duplicator 3.8.7 Backup Disclosure

WordPress Duplicator plugin version 3.8.7 appears to leave backups in a world accessible directory under the document root.

CVE-2023-35043: WordPress Recent Posts Slider plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions.

CVE-2023-33925: WordPress WooCommerce Product Categories Selection Widget plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability - Patchstack

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PluginForage WooCommerce Product Categories Selection Widget plugin <= 2.0 versions.

CVE-2023-23833: WordPress Drop Shadow Boxes plugin <= 1.7.10 - Cross Site Scripting (XSS) vulnerability - Patchstack

Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions.

WordPress Page Builder KingComposer 2.9.6 Open Redirection

WordPress Page Builder KingComposer plugin version 2.9.6 suffers from an open redirection vulnerability.

WordPress Image Optimization 3.8.2 Open Redirection

WordPress Image Optimization plugin version 3.8.2 suffers from an open redirection vulnerability.

CVE-2023-3344

The Auto Location for WP Job Manager via Google WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)