WordPress Plugin Formidable Form Builder-Contact Form, Survey & Quiz Forms for WordPress is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input before being passed to the unserialize() PHP function. Attackers can possibly exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Formidable Form Builder-Contact Form, Survey & Quiz Forms for WordPress version 4.02 is vulnerable; prior versions may also be affected.
Update to plugin version 4.02.03 or latest
WordPress Plugin Testimonial WordPress-AP Custom Testimonial includes Backdoor [Only if downloaded via the vendor website] (1.4.6)
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (4.9.2)
WordPress Plugin BruteBank-WP Security & Firewall Cross-Site Request Forgery (1.8)
WordPress Plugin Ultimate Member-User Profile, User Registration, Login & Membership Security Bypass (2.1.2)
WordPress Plugin ZooEffect for Video player Photo Gallery Slideshow jQuery and audio/music/podcast-HTML Cross-Site Scripting (1.01)