plugin

Alpine Photo Tile For Instagram Vulnerabilities

14 known security issues reported for the Alpine Photo Tile For Instagram WordPress plugin. Most recent disclosed Sep 26, 2019.

4 medium

Running Alpine Photo Tile For Instagram on your site? Check whether your installed version is affected.

Scan your site free

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.7.6 (closed)

unknown

[en] The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.

Affected:
up to 1.2.7.6
Fixed in:
1.2.7.6
Disclosed:
Sep 26, 2019

CVE-2015-9432 on NVD →

Alpine Photo Tile for Instagram < 1.2.10 - Reflected Cross-Site Scripting

medium

The Alpine Photo Tile for Instagram plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘client_id’ parameter in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 1.2.10
Fixed in:
1.2.10
Disclosed:
Mar 1, 2017

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.10

unknown

The Alpine Photo Tile for Instagram plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘client_id’ parameter in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 1.2.10
Fixed in:
1.2.10
Disclosed:
Mar 1, 2017

Alpine PhotoTile for Instagram < 1.2.7.6 - Reflected Cross-Site Scripting

medium

The Alpine PhotoTile for Instagram plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the client_id parameter in versions up to, and including, 1.2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
6.1
Affected:
up to 1.2.7.6
Fixed in:
1.2.7.6
Disclosed:
Aug 20, 2015

CVE-2015-9432 on NVD →

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.7.6 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.2.7.6
Fixed in:
1.2.7.6
Disclosed:
Aug 20, 2015

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
May 14, 2015

Alpine PhotoTile For Instagram < 1.2.9 - Cross-Site Scripting

medium

The Alpine PhotoTile For Instagram plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 1.2.9 due to insufficient input sanitization and output escaping on the 'general_lightbox_params' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute i...

CVSS:
6.1
Affected:
up to 1.2.9
Fixed in:
1.2.9
Disclosed:
Aug 1, 2014

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS:
6.1
Affected:
up to 1.2.7.5
Fixed in:
1.2.7.5
Disclosed:
Aug 1, 2014

CVE-2013-6837 on NVD →

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.6.6 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.2.6.6
Fixed in:
1.2.6.6
Disclosed:
Aug 1, 2014

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.9

unknown

The Alpine PhotoTile For Instagram plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 1.2.9 due to insufficient input sanitization and output escaping on the 'general_lightbox_params' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute i...

Affected:
up to 1.2.9
Fixed in:
1.2.9
Disclosed:
Aug 1, 2014

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.7.5

unknown

[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Affected:
up to 1.2.7.5
Fixed in:
1.2.7.5
Disclosed:
Dec 19, 2013

CVE-2013-6837 on NVD →

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] < 1.2.7.5 (closed)

unknown

The jQuery prettyPhoto library bundled with many plugins was found to be vulnerable to DOM Cross-Site Scripting (XSS).

Affected:
up to 1.2.7.5
Fixed in:
1.2.7.5

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] <= 1.2.7.7 (unfixed + closed)

unknown

The alpine-photo-tile-for-instagram WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.2.7.7
Fix:
No patched version reported

Alpine Photo Tile for Instagram [alpine-photo-tile-for-instagram] <= 1.2.6 (unfixed + closed)

unknown

The alpine-photo-tile-for-instagram WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.2.6
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database