Display Widgets [display-widgets] < 2.04 (closed)
unknown
[en] The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
- Affected:
- up to 2.04
- Fixed in:
- 2.04
- Disclosed:
- Sep 26, 2019
CVE-2015-9438 on NVD →
Display Widgets [display-widgets] < 2.6.3.2 (closed)
unknown
The possible backdoor hacking tool found in WordPress Display Widgets plugin versions 2.6.0-2.6.3.1 by SEO Dave.
Deactivate and remove the WordPress Display Widgets plugin. For now, this plugin removed from WordPress plugin repository.
- Affected:
- up to 2.6.3.2
- Fixed in:
- 2.6.3.2
- Disclosed:
- Sep 10, 2017
Display Widgets [display-widgets] < 2.7
unknown
The Display Widgets plugin for WordPress is vulnerable to a developer-created backdoor that injected SEOspam into sites in versions up to, and including, 2.6.3.1. Any added content is hidden from logged-in users.
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Jun 23, 2017
Display Widgets <= 2.03 - Authenticated Cross-Site Scripting
medium
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
- CVSS:
- 5.4
- Affected:
- up to 2.03
- Fixed in:
- 2.04
- Disclosed:
- Aug 11, 2015
CVE-2015-9438 on NVD →
Display Widgets [display-widgets] < 2.04 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.04
- Fixed in:
- 2.04
- Disclosed:
- Aug 11, 2015
Display Widgets [display-widgets] >= 2.6.0 - <= 2.6.3.1 (closed)
unknown
The display-widgets WordPress plugin was affected by a Backdoored security vulnerability.
- Affected:
- 2.6.0 – 2.6.3.1
- Fixed in:
- 2.6.3.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database