- WordPress Plugin Cimy User Extra Fields is prone to a Denial of Service vulnerability. Exploiting this issue allows an attacker to delete random server files and 'hide' multiple files on the server, thus denying service to legitimate users. WordPress Plugin Cimy User Extra Fields version 2.6.3 is vulnerable; prior versions are also affected.
- Update to plugin version 2.6.4 or latest
- Joomla! Core 1.5.x Spam (1.5.0 - 1.5.6)
- WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (3.5.3)
- WordPress Plugin WP Limit Login Attempts SQL Injection (2.0.0)
- WordPress Plugin Movies Cross-Site Scripting (0.6)
- WordPress Plugin Lazy SEO Arbitrary File Upload (1.3.2)