|
266471
|
6.1 |
MEDIUM
Network
|
sandhillsdev easydigitaldownloads
|
easy_digital_downloads simple_shipping
|
The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9527
|
2024-11-21 11:40 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266472
|
6.1 |
MEDIUM
Network
|
sandhillsdev easydigitaldownloads
|
easy_digital_downloads reviews
|
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x befo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9526
|
2024-11-21 11:40 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266473
|
6.1 |
MEDIUM
Network
|
sandhillsdev easydigitaldownloads
|
easy_digital_downloads recurring_payments
|
The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9525
|
2024-11-21 11:40 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266474
|
6.1 |
MEDIUM
Network
|
artificial_intelligence_project
|
artificial_intelligence
|
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9501
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266475
|
6.1 |
MEDIUM
Network
|
exquisite_ultimate_newspaper_project
|
exquisite_ultimate_newspaper
|
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9500
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266476
|
9.8 |
CRITICAL
Network
|
themepunch
|
showbiz_pro
|
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-9499
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266477
|
8.8 |
HIGH
Network
|
wpserveur
|
wps_hide_login
|
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
|
CWE-352
Origin Validation Error
|
CVE-2015-9498
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266478
|
8.8 |
HIGH
Network
|
ad_inserter_project
|
ad_inserter
|
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
|
CWE-352
Origin Validation Error
|
CVE-2015-9497
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266479
|
8.8 |
HIGH
Network
|
freshmail
|
freshmail-newsletter
|
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
|
CWE-89
SQL Injection
|
CVE-2015-9496
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266480
|
6.1 |
MEDIUM
Network
|
syndication_links_project
|
syndication_links
|
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9495
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|