CVE-2015-9370 – Exchange Addon Invoices < 1.4.0 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9370
Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). El complemento Facturas para iThemes Exchange antes de 1.4.0 para WordPress tiene XSS a través de add_query_arg() y remove_query_arg(). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html https://ithemes.com/coordinated-wordpress-plugin-security-update • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-9376 – iThemes Mobile < 1.2.8 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9376
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg(). iThemes Mobile antes de 1.2.8 para WordPress tiene una vulnerabilidad XSS a través de add_query_arg () y remove_query_arg (). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html https://ithemes.com/coordinated-wordpress-plugin-security-update • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-9366 – Exchange Addon Custom URL Tracking < 1.1.0 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9366
Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). El Add-on Custom URL Tracking para iThemes Exchange versiones anteriores a 1.1.0 para WordPress, tiene una vulnerabilidad de tipo XSS por medio de las funciones add_query_arg() y remove_query_arg(). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html https://ithemes.com/coordinated-wordpress-plugin-security-update • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-9378 – Market < 5.1.27 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9378
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg(). iThemes Builder Theme Market antes de 5.1.27 para WordPress tiene XSS a través de add_query_arg() y remove_query_arg(). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html https://ithemes.com/coordinated-wordpress-plugin-security-update • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-9379 – iThemes Builder Style Manager < 0.7.7 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-9379
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg(). iThemes Builder Style Manager anterior a 0.7.7 para WordPress tiene XSS a través de add_query_arg() y remove_query_arg(). • https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html https://ithemes.com/coordinated-wordpress-plugin-security-update • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •