|
223241
|
6.1 |
MEDIUM
Network
|
wpdownloadmanager
|
wordpress_download_manager
|
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15889
|
2024-11-21 13:29 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223242
|
8.8 |
HIGH
Network
|
metagauss
|
profilegrid
|
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php …
|
CWE-94
Code Injection
|
CVE-2019-15873
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223243
|
9.8 |
CRITICAL
Network
|
wpbrigade
|
loginpress
|
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
|
CWE-89
SQL Injection
|
CVE-2019-15872
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223244
|
4.3 |
MEDIUM
Network
|
wpbrigade
|
loginpress
|
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
|
CWE-862
Missing Authorization
|
CVE-2019-15871
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223245
|
5.4 |
MEDIUM
Network
|
carspot_project
|
carspot
|
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15870
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223246
|
5.4 |
MEDIUM
Network
|
jobcareer_project
|
jobcareer
|
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15869
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223247
|
8.8 |
HIGH
Network
|
wpaffiliatemanager
|
affiliates_manager
|
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15868
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223248
|
8.8 |
HIGH
Network
|
omaksolutions
|
slick-popup
|
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-15867
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223249
|
8.8 |
HIGH
Network
|
crelly_slider_project
|
crelly_slider
|
The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_ajax_crellyslider_importSlider.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15866
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223250
|
8.8 |
HIGH
Network
|
holest
|
breadcrumbs_by_menu
|
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15865
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|