Security Vulnerabilities
- CVEs Published In August 2019
The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.