Security Vulnerabilities
- CVEs Published In August 2019
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
The user-access-manager plugin before 1.2 for WordPress has CSRF.
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.