plugin

Jsmol2Wp Vulnerabilities

4 known security issues reported for the Jsmol2Wp WordPress plugin. Most recent disclosed Jan 7, 2019.

1 high 1 medium

Running Jsmol2Wp on your site? Check whether your installed version is affected.

Scan your site free

JSmol2WP <= 1.07 - Cross-Site Scripting

medium

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.

CVSS:
6.1
Affected:
up to 1.07
Fix:
No patched version reported
Disclosed:
Jan 7, 2019

CVE-2018-20462 on NVD →

JSmol2WP <= 1.07 - Server-Side Request Forgery

high

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

CVSS:
7.5
Affected:
up to 1.07
Fix:
No patched version reported
Disclosed:
Dec 25, 2018

CVE-2018-20463 on NVD →

JSmol2WP [jsmol2wp] <= 1.07 (unfixed + closed)

unknown

[en] An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.

Affected:
up to 1.07
Fix:
No patched version reported
Disclosed:
Dec 25, 2018

CVE-2018-20462 on NVD →

JSmol2WP [jsmol2wp] <= 1.07 (unfixed + closed)

unknown

[en] An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

Affected:
up to 1.07
Fix:
No patched version reported
Disclosed:
Dec 25, 2018

CVE-2018-20463 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database