LocalWeb All In One [lw-all-in-one] < 1.6.5
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Ex.Mi) in WordPress LocalWeb All In One plugin (versions <= 1.6.4).
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- Oct 20, 2020
Web Instant Messenger <= 1.1.2 and LocalWeb In One <= 1.6.4 - Stored Cross-Site Scripting
high
The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 (NOTE: Web Instant Messenger's latest version 1.1.2 is unpatched) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 7.2
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- Oct 12, 2020
LocalWeb All In One [lw-all-in-one] < 1.6.5
unknown
The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 (NOTE: Web Instant Messenger's latest version 1.1.2 is unpatched) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- Oct 12, 2020
LocalWeb All In One [lw-all-in-one] < 1.6.5
unknown
An Unauthenticated Stored XSS vulnerability was discovered in the LocalWeb All In One plugin v1.6.3 for WordPress.
There is an older version of this plugin called Web Instant Messenger, latest version is v1.1.1.
The specificity of this plugin is that it interacts with the remote host www.localweb.it, so the paylo...
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database