Security
Headlines
HeadlinesLatestCVEs

Tag

#wordpress

CVE-2019-15646: RSVPMaker

The rsvpmaker plugin before 6.2 for WordPress has SQL injection.

CVE
#sql#vulnerability#web#google#microsoft#redis#js#git#java#wordpress#php#perl#auth#ssl
CVE-2018-21004

The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.

CVE-2019-15317: WordPress Plugin Give - Stored XSS for Donors

The give plugin before 2.4.7 for WordPress has XSS via a donor name.

CVE-2017-18539: WebLibrarian

The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.

CVE-2015-9320: OptionTree

The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.

CVE-2016-10893: Crayon Syntax Highlighter

The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.

CVE-2019-13578: Fortiguard

A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.