Latest CVE Feed
-
8.8
HIGHCVE-2015-9497
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.... Read more
Affected Products : ad_inserter- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9496
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.... Read more
Affected Products : freshmail-newsletter- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9495
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.... Read more
Affected Products : syndication_links- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9494
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.... Read more
Affected Products : indieweb_post_kinds- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9493
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.... Read more
Affected Products : my_wish_list- Published: Oct. 22, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9492
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate... Read more
Affected Products : smartit_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9491
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrat... Read more
Affected Products : blessing_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9490
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_user... Read more
Affected Products : gamestheme_premium- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9489
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate... Read more
Affected Products : goodnex_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9488
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/upl... Read more
Affected Products : almera_responsive_portfolio_site_template- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9487
The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrat... Read more
Affected Products : almera_responsive_portfolio- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9486
The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/... Read more
Affected Products : axioma_premium_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9485
The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-cont... Read more
Affected Products : accio_responsive_onepage_parallax_site_template- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9484
The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db... Read more
Affected Products : accio_one_page_parallax_responsive_theme- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9483
The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-cont... Read more
Affected Products : invento_\/_architecture_building_agency_template- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9482
The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_d... Read more
Affected Products : car_dealer_\/_auto_dealer_responsive- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9481
The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_us... Read more
Affected Products : diplomat_\|_political- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9480
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.... Read more
Affected Products : robotcpa- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9479
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.... Read more
Affected Products : acf_fronted_display- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9478
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.... Read more
Affected Products : prettyphoto- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024