- WordPress Plugin Simply Static is prone to a vulnerability that lets attackers download arbitrary files because the application fails to sufficiently verify user-supplied input. This may allow an attacker to gain access to sensitive information, which may aid in launching further attacks. WordPress Plugin Simply Static version 1.6.2 is vulnerable; prior versions may also be affected.
- Update to plugin version 1.6.3 or latest
- WordPress Plugin Advanced Text Widget 'page' Parameter Cross-Site Scripting (2.0.0)
- WordPress Plugin SL User Create Information Disclosure (0.2.4)
- WordPress 4.7.x Possible SQL Injection Vulnerability (4.7 - 4.7.6)
- WordPress Plugin Tracking Code Manager Multiple Vulnerabilities (1.11.1)
- WordPress Plugin HTML5 AV Manager for WordPress 'custom.php' Arbitrary File Upload (0.2.7)