|
270021
|
6.1 |
MEDIUM
Network
|
codepeople
|
music_store
|
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10992
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270022
|
7.5 |
HIGH
Network
|
imdb-widget_project
|
imdb-widget
|
The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.
|
CWE-20
Improper Input Validation
|
CVE-2016-10991
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270023
|
6.1 |
MEDIUM
Network
|
wpcerber
|
cerber_security_antispam_\&_malware_scan
|
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10990
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270024
|
8.8 |
HIGH
Network
|
leenk
|
leenk.me
|
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2016-10989
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270025
|
6.1 |
MEDIUM
Network
|
leenk
|
leenk.me
|
The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, facebook_description, default_image, or _wp_http_referer.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10988
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270026
|
6.1 |
MEDIUM
Network
|
woocommerce
|
persian_woocommerce_sms
|
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10987
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270027
|
6.1 |
MEDIUM
Network
|
nerdcow
|
tweet_wheel
|
The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10986
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270028
|
6.1 |
MEDIUM
Network
|
smackcoders
|
echo_sign
|
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10985
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270029
|
6.1 |
MEDIUM
Network
|
smackcoders
|
echo_sign
|
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10984
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270030
|
6.5 |
MEDIUM
Network
|
ghost
|
ghost
|
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
|
CWE-287
Improper Authentication
|
CVE-2016-10983
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|