- WordPress Plugin Ajax Store Locator is prone to a directory traversal vulnerability because it fails to sufficiently sanitize user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Ajax Store Locator version 1.2.0 is vulnerable; prior versions may also be affected.
- Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
- WordPress Plugin WordPress Social Login Cross-Site Scripting (2.0.3)
- WordPress Plugin Dean's FCKEditor with pwwang's code Arbitrary File Upload (1.0.0)
- WordPress Plugin Royal Gallery Cross-Site Scripting (2.0)
- WordPress Plugin WordPress Responsive Preview Cross-Site Scripting (1.1)
- WordPress Plugin wpForo Forum Cross-Site Scripting (1.4.11)