WordPress Landing Pages [landing-pages] < 1.8.8 (closed)
unknown
[en] A vulnerability, which was classified as problematic, has been found in Landing Pages Plugin up to 1.8.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.8 is able to address this issue....
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Mar 5, 2023
CVE-2015-10090 on NVD →
WordPress Landing Pages [landing-pages] < 1.8.8
unknown
[en] The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 14, 2019
CVE-2015-9311 on NVD →
WordPress Landing Pages [landing-pages] < 1.9.2 (closed)
unknown
[en] The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Oct 18, 2017
CVE-2015-5227 on NVD →
WordPress Landing Pages [landing-pages] < 1.8.8 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Upgrade the plugin.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Aug 4, 2016
WordPress Landing Pages [landing-pages] < 1.2.3 (closed)
unknown
This plugin is prone to a module.redirect-ab-testing.php permalink_name parameter SQL injection vulnerability.
Update the plugin.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Aug 4, 2016
WordPress Landing Pages [landing-pages] < 2.2.5 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Upgrade this plugin.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Aug 3, 2016
WordPress Landing Pages <= 2.2.4 - Cross-Site Scripting
medium
The WordPress Landing Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘open-tab' parameter in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 5.4
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Jul 1, 2016
WordPress Landing Pages [landing-pages] < 2.2.5
unknown
The WordPress Landing Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘open-tab' parameter in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Jul 1, 2016
WordPress Landing Pages <= 1.9.0 - Unauthenticated Remote Command Execution
high
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
- CVSS:
- 8.8
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Sep 30, 2015
CVE-2015-5227 on NVD →
WordPress Landing Pages <= 1.8.7 - Cross-Site Scripting
medium
The WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.8.7
- Fixed in:
- 1.8.8
- Disclosed:
- Jun 15, 2015
CVE-2015-10090 on NVD →
WordPress Landing Pages [landing-pages] < 1.8.5 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- May 27, 2015
CVE-2015-4065 on NVD →
WordPress Landing Pages [landing-pages] < 1.8.5 (closed)
unknown
[en] SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- May 27, 2015
CVE-2015-4064 on NVD →
WordPress Landing Pages <= 1.8.4 - Authenticated SQL Injection
high
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.
- CVSS:
- 8.8
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- May 25, 2015
CVE-2015-4064 on NVD →
WordPress Landing Pages <= 1.8.4 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.
- CVSS:
- 6.5
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- May 25, 2015
CVE-2015-4065 on NVD →
WordPress Landing Pages [landing-pages] < 1.2.3 (closed)
unknown
[en] SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Oct 23, 2013
CVE-2013-6243 on NVD →
WordPress Landing Pages < 1.2.3 - SQL Injection
critical
SQL injection vulnerability in the Landing Pages plugin before 1.2.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.
- CVSS:
- 9.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Oct 10, 2013
CVE-2013-6243 on NVD →
WordPress Landing Pages [landing-pages] < 2.2.5 (closed)
unknown
The WordPress Landing Pages WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
WordPress Landing Pages [landing-pages] < 1.2.3 (closed)
unknown
The WordPress Landing Pages WordPress plugin was affected by a module.redirect-ab-testing.php permalink_name Parameter SQL Injection security vulnerability.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database