- WordPress Plugin FireStats is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin FireStats version 1.6.5 is vulnerable; prior versions may also be affected.
- Update to plugin version 1.6.6 or latest
- WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.9.51)
- WordPress Plugin WP-Cal 'id' Parameter SQL Injection (0.3)
- WordPress Plugin BuddyPress Multiple Vulnerabilities (1.9.1)
- WordPress Plugin NextGEN Smooth Gallery 'galleryID' Parameter SQL Injection (1.2)
- WordPress Plugin Custom Post Type UI 'wp-admin/admin.php' Cross-Site Scripting (0.7)