- WordPress Plugin Advanced Dewplayer is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Advanced Dewplayer version 1.2 is vulnerable; prior versions may also be affected.
- Update to plugin version 1.3 or latest
- WordPress 4.0.x Possible SQL Injection Vulnerability (4.0 - 4.0.19)
- WordPress Plugin BackWPup 'wp_export_generate.php' Local and Remote File Include Vulnerabilities (2.1.4)
- WordPress Plugin S3Bubble Cloud Video With Adverts & Analytics Arbitrary File Download (0.7)
- WordPress Plugin Add Social Share Messenger Buttons Whatsapp and Viber Cross-Site Request Forgery (1.0.8)
- WordPress Plugin Comment Extra Fields Multiple Cross-Site Scripting Vulnerabilities (1.7)