Page 7 of 40 results (0.006 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter. Múltiples vulnerabilidades de Cross-Site Scripting (XSS) en las funciones (1) cp_updateMessageItem y (2) cp_deleteMessageItem en cp_ppp_admin_int_message_list.inc.php en el plugin Payment Form for PayPal Pro, en versiones anteriores a la 1.0.2 para WordPress, permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante el parámetro cal. WordPress DWBooster Payment Form for PayPal Pro plugin version 1.0.1 suffers from a cross site scripting vulnerability. • http://www.securityfocus.com/archive/1/536602/100/0/threaded https://plugins.trac.wordpress.org/changeset/1254452/payment-form-for-paypal-pro https://wordpress.org/plugins/payment-form-for-paypal-pro/#developers https://wpvulndb.com/vulnerabilities/8210 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username. Vulnerabilidad de inyección SQL en cpabc_appointments_admin_int_calendar_list.inc.php en el plugin Appointment Booking Calendar en versiones anteriores a 1.1.8 para WordPress, permite a atacantes remotos ejecutar comandos SQL arbitrarios a través vectores no especificados relacionados con la actualización del nombre de usuario. • http://packetstormsecurity.com/files/133757/WordPress-Appointment-Booking-Calendar-1.1.7-SQL-Injection.html http://www.securityfocus.com/archive/1/536555/100/0/threaded https://wordpress.org/plugins/appointment-booking-calendar/changelog https://wpvulndb.com/vulnerabilities/8199 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en cpabc_appointments_admin_int_bookings_list.inc.php en el plugin Appointment Booking Calendar en versiones anteriores a 1.1.8 para WordPress, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. WordPress Appointment Booking Calendar plugin version 1.1.7 suffers from multiple cross site scripting vulnerabilities. • http://packetstormsecurity.com/files/133743/WordPress-Appointment-Booking-Calendar-1.1.7-XSS.html http://www.securityfocus.com/archive/1/536556/100/0/threaded http://www.securityfocus.com/archive/1/536557/100/0/threaded https://wordpress.org/plugins/appointment-booking-calendar/changelog https://wpvulndb.com/vulnerabilities/8199 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs. El plugin sell-downloads versiones anteriores a 1.0.8 para WordPress, tiene restricciones insuficientes para adivinar mediante fuerza bruta los IDs de compra. • https://wordpress.org/plugins/sell-downloads/#developers • CWE-20: Improper Input Validation •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. Las versiones anteriores a la 1.1.6 del plugin cp-contact-form-with-paypal (también llamado CP Contact Form with PayPal) para WordPress tienen Cross-Site Request Forgery (CSRF) con Cross-Site Scripting (XSS) resultante. Esto está relacionado con cp_contactformpp.php y cp_contactformpp_admin_int_list.inc.php. • http://seclists.org/fulldisclosure/2015/Jul/49 http://seclists.org/oss-sec/2015/q3/88 https://wordpress.org/plugins/cp-contact-form-with-paypal/#developers • CWE-352: Cross-Site Request Forgery (CSRF) •