Tag
#wordpress
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.