Description
Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin FileBird-WordPress Media Library Folders & File Manager Cross-Site Scripting (2.4)
WordPress Plugin Leaky Paywall PHP Object Injection (4.9.1)
WebLogic CVE-2016-0572 Vulnerability (CVE-2016-0572)
WordPress Plugin Float to Top Button Cross-Site Scripting (2.3.6)
WordPress Plugin Resize Image After Upload Cross-Site Request Forgery (1.8.5)