CVE-2015-9362 – Post Connector < 1.0.4 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9362
The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg(). El plugin Post Connector versiones anteriores a 1.0.4 para WordPress, tiene una vulnerabilidad de tipo XSS por medio de las funciones add_query_arg() y remove_query_arg(). • https://www.barrykooij.com/several-security-updates-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-9361 – Related Posts <= 1.8.1 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9361
The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg(). El plugin Related Posts versiones anteriores a 1.8.2 para WordPress, tiene una vulnerabilidad de tipo XSS por medio de las funciones add_query_arg() y remove_query_arg(). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html https://www.barrykooij.com/several-security-updates-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •