- WordPress Plugin ChimpMate-WordPress MailChimp Assistant is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin ChimpMate-WordPress MailChimp Assistant version 1.3.2 is vulnerable; prior versions may also be affected.
- Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
- WordPress Plugin Homepage SlideShow 'upload.php' Arbitrary File Upload (2.0)
- WordPress Plugin Smush Image Compression and Optimization Multiple Vulnerabilities (2.9.1)
- WordPress Plugin EMC2 Custom Help Videos Cross-Site Scripting (1.2)
- WordPress Plugin WP Photo Album 'photo' Parameter SQL Injection (1.0)
- WordPress Plugin WP Idea Stream Cross-Site Scripting (2.1.1)