Tag
#wordpress
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.