Joomla! Core is prone to an open redirect vulnerability because the application fails to properly validate user-supplied input. Exploiting this issue may allow attackers to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. Joomla! Core versions 3.x.x ranging from 3.0.0 and up to and including 3.9.20 are vulnerable.
Update to Joomla! Core version 3.9.21 or latest
WordPress Plugin WooCommerce Checkout Manager Multiple Unspecified Vulnerabilities (3.6.9)
WordPress Plugin WP Statistics Cross-Site Scripting (12.0.9)
WordPress 3.0.3 KSES Library Cross-Site Scripting Vulnerability (0.6.2 - 3.0.3)
WordPress Plugin Custom Login Redirect Cross-Site Request Forgery (1.0.0)
WordPress Plugin Custom Permalinks Unspecified Vulnerability (0.7.15)