Latest CVE Feed
-
8.8
HIGHCVE-2016-11003
The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.... Read more
Affected Products : monarch- EPSS Score: %0.20
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-11002
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.... Read more
Affected Products : extra- EPSS Score: %0.20
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-11001
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.... Read more
Affected Products : user_submitted_posts- EPSS Score: %0.17
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-11000
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.... Read more
Affected Products : ultimate_exporter- EPSS Score: %0.55
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10999
The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.... Read more
Affected Products : goodnews- EPSS Score: %0.19
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10998
The ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS.... Read more
Affected Products : ocim-mp3- EPSS Score: %0.19
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-10997
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.... Read more
Affected Products : beauty-premium- EPSS Score: %0.19
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-10996
The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.... Read more
Affected Products : optinmonster- EPSS Score: %0.16
- Published: Sep. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10995
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.... Read more
Affected Products : telvolution- EPSS Score: %0.84
- Published: Sep. 18, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10994
The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter.... Read more
Affected Products : truemag_theme- EPSS Score: %0.94
- Published: Sep. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-10993
The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter.... Read more
Affected Products : scoreme- EPSS Score: %6.28
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10992
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter.... Read more
Affected Products : music_store- EPSS Score: %0.26
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-10991
The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.... Read more
Affected Products : imdb-widget- EPSS Score: %0.60
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10990
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.... Read more
Affected Products : cerber_security_antispam_\&_malware_scan- EPSS Score: %1.19
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-10989
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.... Read more
Affected Products : leenk.me- EPSS Score: %0.24
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10988
The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, facebook_description, default_image, or _wp_http_referer.... Read more
Affected Products : leenk.me- EPSS Score: %0.24
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10987
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.... Read more
Affected Products : persian_woocommerce_sms- EPSS Score: %0.26
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10986
The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_token_secret.... Read more
Affected Products : tweet_wheel- EPSS Score: %0.24
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10985
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.... Read more
Affected Products : echo_sign- EPSS Score: %0.24
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-10984
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.... Read more
Affected Products : echo_sign- EPSS Score: %0.24
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024