Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown
CVE-2016-10866
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown
CVE-2016-10867
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
0
Attacker Value
Unknown
CVE-2015-9293
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
0
Attacker Value
Unknown
CVE-2016-10868
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and file change detection settings pages.
0
Attacker Value
Unknown
CVE-2015-9294
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
0
Attacker Value
Unknown
CVE-2014-5072
Disclosure Date: April 06, 2018 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2018-8719
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.
0
Attacker Value
Unknown
CVE-2012-4263
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
0
Attacker Value
Unknown
CVE-2012-4264
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.
0