
CVE-2016-1000132 – CM Tooltip Glossary – Better SEO and UEX for your WP site <= 3.3.4 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-1000132
10 Oct 2016 — Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8 Vulnerabilidad de XSS reflejada en el plugin de wordpress enhanced-tooltipglossary v3.2.8 Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.3.4 via the itemsnumber parameter. • http://www.securityfocus.com/bid/93865 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-9129 – CM Download Manager <= 2.0.6 - Cross-Site Request Forgery to Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2014-9129
01 Dec 2014 — Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php. Vulnerabilidad de CSRF en el plugin CreativeMinds CM Downloads Manager anterior a 2.0.7 para WordPress permite a atacantes remotos secuestrar la autenticación de administ... • https://packetstorm.news/files/id/129357 • CWE-352: Cross-Site Request Forgery (CSRF) •