
CVE-2019-9646 – Contact Form Email <= 1.2.65 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-9646
05 Feb 2019 — The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area." El plugin Contact Form Email, en versiones anteriores a la 1.2.66 para WordPress, permite Cross-Site Scripting (XSS) en los ítems wp-admin/admin.php. Esto está relacionado con cp_admin_int_edition.inc.php en el área "custom edition area". WordPress Contact Form Email plugin version 1.2.65 suffers from cross site request forgery and cross site scr... • https://packetstorm.news/files/id/151547 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-10992 – Music Store <= 1.0.41 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-10992
28 Mar 2016 — The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter. El plugin music-store versiones anteriores a 1.0.43 para WordPress, presenta una vulnerabilidad de tipo XSS por medio del parámetro from_year de wp-admin/admin.php?page=music-store-menu-reports. • https://packetstormsecurity.com/files/136445 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-10908 – Booking Calendar Contact Form <= 1.0.23 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-10908
08 Feb 2016 — The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS. El plugin booking-calendar-contact-form antes de 1.0.24 para WordPress tiene XSS. The Booking Calendar Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 1.0.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succes... • https://wordpress.org/plugins/booking-calendar-contact-form/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-10909 – Booking Calendar Contact Form < 1.0.24 - Blind SQL Injection
https://notcve.org/view.php?id=CVE-2016-10909
08 Feb 2016 — The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. El plugin booking-calendar-contact-form antes de 1.0.24 para WordPress tiene inyección SQL The Booking Calendar Contact Form plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in versions up to, and including, 1.0.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append addition... • https://wordpress.org/plugins/booking-calendar-contact-form/#developers • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2016-10916 – Appointment Booking Calendar <= 1.1.23 - SQL Injection
https://notcve.org/view.php?id=CVE-2016-10916
25 Jan 2016 — The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. El plugin appointment-booking-calendar versiones anteriores a 1.1.24 para WordPress, presenta una inyección SQL, una vulnerabilidad diferente de CVE-2015-7319. • https://wordpress.org/plugins/appointment-booking-calendar/#developers • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-7666 – Payment Form for PayPal Pro < 1.0.2 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-7666
04 Oct 2015 — Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en las funciones (1) cp_updateMessageItem y (2) cp_deleteMessageItem en cp_ppp_admin_int_message_list.inc.php en el plugin Payment Form f... • https://packetstorm.news/files/id/133857 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-7319 – Appointment Booking Calendar <= 1.1.7 - SQL Injection
https://notcve.org/view.php?id=CVE-2015-7319
26 Sep 2015 — SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username. Vulnerabilidad de inyección SQL en cpabc_appointments_admin_int_calendar_list.inc.php en el plugin Appointment Booking Calendar en versiones anteriores a 1.1.8 para WordPress, permite a atacantes remotos ejecutar comandos SQL arbitrarios a trav... • http://packetstormsecurity.com/files/133757/WordPress-Appointment-Booking-Calendar-1.1.7-SQL-Injection.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2015-7320 – Appointment Booking Calendar <= 1.1.7 - Multiple Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-7320
26 Sep 2015 — Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en cpabc_appointments_admin_int_bookings_list.inc.php en el plugin Appointment Booking Calendar en versiones anteriores a 1.1.8 para WordPress, permite a atacantes remotos inyectar secuencias de comandos web o HTML ... • https://packetstorm.news/files/id/133743 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-9348 – Sell Downloads <= 1.0.7 - Improper Input Validation
https://notcve.org/view.php?id=CVE-2015-9348
10 Jul 2015 — The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs. El plugin sell-downloads versiones anteriores a 1.0.8 para WordPress, tiene restricciones insuficientes para adivinar mediante fuerza bruta los IDs de compra. • https://wordpress.org/plugins/sell-downloads/#developers • CWE-20: Improper Input Validation •

CVE-2015-9233 – CP Contact Form with PayPal < 1.1.6 - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2015-9233
09 Jul 2015 — The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. Las versiones anteriores a la 1.1.6 del plugin cp-contact-form-with-paypal (también llamado CP Contact Form with PayPal) para WordPress tienen Cross-Site Request Forgery (CSRF) con Cross-Site Scripting (XSS) resultante. Esto está relacionado con cp_contactformpp.php y cp_contactformpp_admin_int_list.inc.p... • http://seclists.org/fulldisclosure/2015/Jul/49 • CWE-352: Cross-Site Request Forgery (CSRF) •