- WordPress Plugin Ajax Load More is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. WordPress Plugin Ajax Load More version 188.8.131.52 is vulnerable; prior versions may also be affected.
- Update to plugin version 184.108.40.206 or latest
- WordPress Plugin Mingle Forum 'edit_post_id' Parameter SQL Injection (1.0.31)
- Apache Tomcat version older than 6.0.16
- WordPress Plugin Swipe Checkout for Jigoshop Cross-Site Scripting (3.1.0)
- WordPress Plugin User Self Delete SQL Injection (1.1)
- WordPress Plugin Contact Form DB Multiple Cross-Site Scripting Vulnerabilities (2.8.15)