Tag
#wordpress
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
The Headway theme before 3.8.9 for WordPress has XSS via the license key field.
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.