|
267531
|
8.8 |
HIGH
Network
|
ad_inserter_project
|
ad_inserter
|
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
|
CWE-352
Origin Validation Error
|
CVE-2015-9497
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267532
|
8.8 |
HIGH
Network
|
freshmail
|
freshmail-newsletter
|
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
|
CWE-89
SQL Injection
|
CVE-2015-9496
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267533
|
6.1 |
MEDIUM
Network
|
syndication_links_project
|
syndication_links
|
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9495
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267534
|
6.1 |
MEDIUM
Network
|
indieweb_post_kinds_project
|
indieweb_post_kinds
|
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9494
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267535
|
6.1 |
MEDIUM
Network
|
nlb-creationst
|
my_wish_list
|
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9493
|
2024-11-21 11:40 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267536
|
7.5 |
HIGH
Network
|
smartit_premium_responsive_project
|
smartit_premium_responsive
|
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a …
|
CWE-200
Information Exposure
|
CVE-2015-9492
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267537
|
7.5 |
HIGH
Network
|
blessing_premium_responsive_project
|
blessing_premium_responsive
|
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a…
|
CWE-200
Information Exposure
|
CVE-2015-9491
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267538
|
7.5 |
HIGH
Network
|
gamestheme_premium_project
|
gamestheme_premium
|
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct r…
|
CWE-200
Information Exposure
|
CVE-2015-9490
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267539
|
7.5 |
HIGH
Network
|
goodnex_premium_responsive_project
|
goodnex_premium_responsive
|
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a …
|
CWE-200
Information Exposure
|
CVE-2015-9489
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267540
|
7.5 |
HIGH
Network
|
almera_responsive_portfolio_site_template_project
|
almera_responsive_portfolio_site_template
|
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_e…
|
CWE-200
Information Exposure
|
CVE-2015-9488
|
2024-11-21 11:40 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|