[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <14833966e3c.f43a443960037.3741503082944933346@vexatioustendencies.com>
Date: Mon, 01 Sep 2014 16:44:49 -0700
From: "Voxel@...ht" <voxelnight@...atioustendencies.com>
To: <fulldisclosure@...lists.org>
Subject: [FD] Wordpress Plugin Vulnerability Dump - Part 1
Multiple vulnerabilities in multiple plugins:
Easy Media Gallery v1.2.59 - CSRF (leading to XSS)
WP RSS Multi Importer v3.11 - CSRF
Ready! Ecommerce v0.5.0 - CSRF, XSS
Ready! Google Maps v1.1.5 - CSRF (leading to XSS)
Ready! Coming Soon v0.5.0 - CSRF, XSS
Contact Form v3.82 - (minor) CSRF
WP Photo Album Plus v5.4.5 - XSS
Details and POCs located: https://vexatioustendencies.com/wordpress-plugin-vulnerability-dump-part-1/
(Many) more to follow.
-Voxel@...ht
_______________________________________________
Sent through the Full Disclosure mailing list
http://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists