plugin

Pay With Tweet Vulnerabilities

4 known security issues reported for the Pay With Tweet WordPress plugin. Most recent disclosed Oct 9, 2012.

1 high 1 medium

Running Pay With Tweet on your site? Check whether your installed version is affected.

Scan your site free

Pay With Tweet [pay-with-tweet] < 1.2 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Oct 9, 2012

CVE-2012-5349 on NVD →

Pay With Tweet [pay-with-tweet] < 1.2 (closed)

unknown

[en] SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Oct 9, 2012

CVE-2012-5350 on NVD →

Pay With Tweet <= 1.1 - Authenticated SQL Injection

high

SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.

CVSS:
8.8
Affected:
up to 1.1
Fixed in:
1.2
Disclosed:
Jan 6, 2012

CVE-2012-5350 on NVD →

Pay With Tweet <= 1.1 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.

CVSS:
6.1
Affected:
up to 1.1
Fixed in:
1.2
Disclosed:
Jan 6, 2012

CVE-2012-5349 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database