- WordPress Plugin Cimy Counter is prone to an HTTP response-splitting vulnerability and a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, and influence how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust. WordPress Plugin Cimy Counter versions prior to 0.9.5 are vulnerable.
- Update to the latest version
- WordPress Plugin ProPlayer 'pp_playlist_id' Parameter SQL Injection (4.7.7)
- Joomla! Core 2.5.x Information Disclosure (2.5.0 - 2.5.9)
- WordPress Plugin BuddyPress Cross-Site Scripting (18.104.22.168)
- WordPress Plugin Social Media and Share Icons (Ultimate Social Media) Cross-Site Scripting (22.214.171.124)
- WordPress Plugin My Page Order Cross-Site Scripting (4.3)