plugin

Jrss Widget Vulnerabilities

3 known security issues reported for the Jrss Widget WordPress plugin. Most recent disclosed Dec 5, 2014.

1 high

Running Jrss Widget on your site? Check whether your installed version is affected.

Scan your site free

jRSS Widget [jrss-widget] <= 1.2 (closed)

unknown

[en] Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Dec 5, 2014

CVE-2014-9292 on NVD →

jRSS Widget <= 1.2 - Server-Side Request Forgery

high

Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.

CVSS:
7.5
Affected:
up to 1.2
Fix:
No patched version reported
Disclosed:
May 28, 2014

CVE-2014-9292 on NVD →

jRSS Widget [jrss-widget] < 1.1.2 (closed)

unknown

This jRSS Widget plugin is prone to an information-disclosure vulnerability. Application fails to validate user-supplied data. Because of this issue, an attacker can view local files in the context of the affected application. In that way, the attacker obtains sensitive information. Other attacks are also possible.

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Nov 8, 2010

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database