- WordPress Plugin eShop is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input. Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process; this may result in total compromise of the web server. WordPress Plugin eShop version 6.3.11 is vulnerable; prior versions may also be affected.
- Edit the source code to ensure that input is properly validated or disable the plugin until a fix is available
- WordPress Plugin WP Post to PDF Cross-Site Scripting (2.3.1)
- WordPress Plugin SI CAPTCHA Anti-Spam Cross-Site Scripting (2.7.5)
- WordPress Plugin Facebook Opengraph Meta 'all_meta.php' SQL Injection (1.0)
- WordPress Plugin Traffic Manager Multiple Vulnerabilities (1.4.5)
- WordPress Plugin Contact Form by WD-responsive drag & drop contact form builder tool Multiple Vulnerabilities (1.12.20)