plugin

Intouch Vulnerabilities

5 known security issues reported for the Intouch WordPress plugin. Most recent disclosed Aug 1, 2014.

1 medium

Running Intouch on your site? Check whether your installed version is affected.

Scan your site free

intouch [intouch] < 2.1 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in intouch.js.php intouch_failure parameter. Update the plugin.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Aug 1, 2014

intouch [intouch] < 2.1 (closed)

unknown

This plugin is prone to a cross site scripting vulnerability in intouch.js.php intouch_failure parameter. Update the plugin.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Aug 1, 2014

intouch <= 2.0 - Cross-Site Scripting

medium

The intouch plugin for WordPress is vulnerable to Cross-Site Scripting via the 'intouch_failure' parameter in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Jan 1, 2014

intouch [intouch] <= 2.0 (unfixed)

unknown

The intouch plugin for WordPress is vulnerable to Cross-Site Scripting via the 'intouch_failure' parameter in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Jan 1, 2014

intouch [intouch] <= 2.0 (unfixed + closed)

unknown

The intouch WordPress plugin was affected by an intouch.js.php intouch_failure Parameter Reflected XSS security vulnerability.

Affected:
up to 2.0
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database