plugin

Landing Pages Vulnerabilities

18 known security issues reported for the Landing Pages WordPress plugin. Most recent disclosed Mar 5, 2023.

1 critical 2 high 3 medium

Running Landing Pages on your site? Check whether your installed version is affected.

Scan your site free

WordPress Landing Pages [landing-pages] < 1.8.8 (closed)

unknown

[en] A vulnerability, which was classified as problematic, has been found in Landing Pages Plugin up to 1.8.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.8.8 is able to address this issue....

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Mar 5, 2023

CVE-2015-10090 on NVD →

WordPress Landing Pages [landing-pages] < 1.8.8

unknown

[en] The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Aug 14, 2019

CVE-2015-9311 on NVD →

WordPress Landing Pages [landing-pages] < 1.9.2 (closed)

unknown

[en] The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Oct 18, 2017

CVE-2015-5227 on NVD →

WordPress Landing Pages [landing-pages] < 1.8.8 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade the plugin.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Aug 4, 2016

WordPress Landing Pages [landing-pages] < 1.2.3 (closed)

unknown

This plugin is prone to a module.redirect-ab-testing.php permalink_name parameter SQL injection vulnerability. Update the plugin.

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Aug 4, 2016

WordPress Landing Pages [landing-pages] < 2.2.5 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade this plugin.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Aug 3, 2016

WordPress Landing Pages <= 2.2.4 - Cross-Site Scripting

medium

The WordPress Landing Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘open-tab' parameter in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
5.4
Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Jul 1, 2016

WordPress Landing Pages [landing-pages] < 2.2.5

unknown

The WordPress Landing Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘open-tab' parameter in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Jul 1, 2016

WordPress Landing Pages <= 1.9.0 - Unauthenticated Remote Command Execution

high

The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.

CVSS:
8.8
Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Sep 30, 2015

CVE-2015-5227 on NVD →

WordPress Landing Pages <= 1.8.7 - Cross-Site Scripting

medium

The WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.8.7
Fixed in:
1.8.8
Disclosed:
Jun 15, 2015

CVE-2015-10090 on NVD →

WordPress Landing Pages [landing-pages] < 1.8.5 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
May 27, 2015

CVE-2015-4065 on NVD →

WordPress Landing Pages [landing-pages] < 1.8.5 (closed)

unknown

[en] SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
May 27, 2015

CVE-2015-4064 on NVD →

WordPress Landing Pages <= 1.8.4 - Authenticated SQL Injection

high

SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

CVSS:
8.8
Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
May 25, 2015

CVE-2015-4064 on NVD →

WordPress Landing Pages <= 1.8.4 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.

CVSS:
6.5
Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
May 25, 2015

CVE-2015-4065 on NVD →

WordPress Landing Pages [landing-pages] < 1.2.3 (closed)

unknown

[en] SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Oct 23, 2013

CVE-2013-6243 on NVD →

WordPress Landing Pages < 1.2.3 - SQL Injection

critical

SQL injection vulnerability in the Landing Pages plugin before 1.2.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.

CVSS:
9.8
Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Oct 10, 2013

CVE-2013-6243 on NVD →

WordPress Landing Pages [landing-pages] < 2.2.5 (closed)

unknown

The WordPress Landing Pages WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.2.5
Fixed in:
2.2.5

WordPress Landing Pages [landing-pages] < 1.2.3 (closed)

unknown

The WordPress Landing Pages WordPress plugin was affected by a module.redirect-ab-testing.php permalink_name Parameter SQL Injection security vulnerability.

Affected:
up to 1.2.3
Fixed in:
1.2.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database