Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2016-10866

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown

CVE-2016-10867

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
Attacker Value
Unknown

CVE-2015-9293

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
0
Attacker Value
Unknown

CVE-2016-10868

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
0
Attacker Value
Unknown

CVE-2015-9294

Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
0
Attacker Value
Unknown

CVE-2014-5072

Disclosure Date: April 06, 2018 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2018-8719

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.
0
Attacker Value
Unknown

CVE-2012-4263

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
0
Attacker Value
Unknown

CVE-2012-4264

Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.
0