- WordPress Plugin AlertWire is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin AlertWire version 1.1.1 is vulnerable; prior versions may also be affected.
- Edit the source code to ensure that errors containing sensitive information aren't displayed to the end user or disable the plugin until a fix is available
- WordPress Plugin SP Project & Document Manager SQL Injection (2.5.3)
- WordPress Plugin User registration & user profile-Profile Builder 'key' Parameter Security Bypass (1.1.24)
- WordPress Plugin WooCommerce Products Filter Multiple Vulnerabilities (1.1.9)
- WordPress Plugin Spotlight Cross-Site Scripting (4.7)
- WordPress Plugin Search Unleashed 'Log' Function HTML Injection (0.2.10)