plugin

Gocodes Vulnerabilities

3 known security issues reported for the Gocodes WordPress plugin. Most recent disclosed Nov 24, 2015.

1 critical 1 high 1 medium

Running Gocodes on your site? Check whether your installed version is affected.

Scan your site free

GoCodes <= 1.3.5 - Authenticated XSS & Blind SQL Injection

critical
Fix:
No patched version reported
Disclosed:
Nov 24, 2015

CVE-2015-9398 on NVD →

GoCodes <= 1.3.5 - Authenticated Blind SQL Injection

high

The GoCodes plugin for WordPress is vulnerable to blind SQL Injection via the ‘gcid’ parameter in versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for editor-level attackers to append ad...

CVSS:
8.8
Affected:
up to 1.3.5
Fix:
No patched version reported
Disclosed:
Aug 25, 2015

CVE-2015-9398 on NVD →

GoCodes <= 1.3.5 - Cross-Site Scripting

medium

The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS.

CVSS:
5.4
Affected:
up to 1.3.5
Fix:
No patched version reported
Disclosed:
Aug 25, 2015

CVE-2015-9397 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database