|
211211
|
8.8 |
HIGH
Network
|
simpolio_project
|
simpolio
|
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
|
CWE-276
Incorrect Default Permissions
|
CVE-2015-9474
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211212
|
7.5 |
HIGH
Network
|
estrutura-basica_project
|
estrutura-basica
|
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
|
CWE-22
Path Traversal
|
CVE-2015-9473
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211213
|
6.1 |
MEDIUM
Network
|
monitorbacklinks
|
incoming_links
|
The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9472
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211214
|
9.8 |
CRITICAL
Network
|
digitalzoomstudio
|
zoomsounds
|
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-9471
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211215
|
7.5 |
HIGH
Network
|
ionadas
|
history_collection
|
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
|
CWE-22
Path Traversal
|
CVE-2015-9470
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211216
|
4.8 |
MEDIUM
Network
|
cybercraftit
|
content-grabber
|
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9469
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211217
|
6.1 |
MEDIUM
Network
|
k-78
|
broken_link_manager
|
The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9468
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211218
|
9.8 |
CRITICAL
Network
|
k-78
|
broken_link_manager
|
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
|
CWE-89
SQL Injection
|
CVE-2015-9467
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211219
|
9.8 |
CRITICAL
Network
|
webtechideas
|
wti_like_post
|
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED vari…
|
CWE-89
SQL Injection
|
CVE-2015-9466
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211220
|
8.8 |
HIGH
Network
|
yet_another_stars_rating_project
|
yet_another_stars_rating
|
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.
|
CWE-89
SQL Injection
|
CVE-2015-9465
|
2024-11-21 11:40 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|