Media Library Categories <= 1.1.1 - Unauthenticated Multiple Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Media Library Categories plugin 1.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) bulk parameter to media-library-categories/add.php or (2) q parameter to media-library-categories/view.php.
- CVSS:
- 6.1
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014
CVE-2012-6630 on NVD →
Media Library Categories [media-library-categories] <= 1.0.6 (closed)
unknown
This Media Library Categories plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 6, 2011
Media Library Categories [media-library-categories] <= 1.0.6 (unfixed + closed)
unknown
The media-library-categories WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database