- The Parallels Plesk Panel software package is a commercial web hosting automation program. Parallels Plesk Single Sign-On (SSO) technology make it easy for customers to use and manage applications, and reduce the administrative costs of password management for hosting providers. Parallels Plesk Single Sign-On (SSO) implementation was found vulnerable to XXE (XML External Entity) and XSS (Cross-site scripting) vulnerabilities.
To disable SSO-mode in Parallels Plesk Panel:
~# /usr/local/psa/bin/sso --disable
- WordPress Plugin MobileChief-Mobile Site Builder Cross-Site Scripting (1.5.7)
- WordPress Plugin Walk Score Multiple Cross-Site Scripting Vulnerabilities (0.5.5)
- WordPress Plugin Newsletter Cross-Site Scripting (3.2.6)
- WordPress Plugin iThemes Security (formerly Better WP Security) Multiple Cross-Site Scripting Vulnerabilities (3.4.3)
- WordPress Plugin Plug-N-Edit Full Drag & Drop HTML Visual Editor with Web Page Builder WYSIWYG Cross-Site Scripting (5.2.0)