|
265821
|
6.1 |
MEDIUM
Network
|
wpcerber
|
cerber_security_antispam_\&_malware_scan
|
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10990
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265822
|
8.8 |
HIGH
Network
|
leenk
|
leenk.me
|
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2016-10989
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265823
|
6.1 |
MEDIUM
Network
|
leenk
|
leenk.me
|
The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, facebook_description, default_image, or _wp_http_referer.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10988
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265824
|
6.1 |
MEDIUM
Network
|
woocommerce
|
persian_woocommerce_sms
|
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10987
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265825
|
6.1 |
MEDIUM
Network
|
nerdcow
|
tweet_wheel
|
The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10986
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265826
|
6.1 |
MEDIUM
Network
|
smackcoders
|
echo_sign
|
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10985
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265827
|
6.1 |
MEDIUM
Network
|
smackcoders
|
echo_sign
|
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10984
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265828
|
6.5 |
MEDIUM
Network
|
ghost
|
ghost
|
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
|
CWE-287
Improper Authentication
|
CVE-2016-10983
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265829
|
8.8 |
HIGH
Network
|
kentothemes
|
kento-post-view-counter
|
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2016-10982
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265830
|
6.1 |
MEDIUM
Network
|
kentothemes
|
kento-post-view-counter
|
The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_text, or kento_pvc_total_text.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10981
|
2024-11-21 11:45 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|