plugin

Register Plus Vulnerabilities

4 known security issues reported for the Register Plus WordPress plugin. Most recent disclosed Dec 4, 2010.

1 high 1 medium

Running Register Plus on your site? Check whether your installed version is affected.

Scan your site free

Register Plus [register-plus] <= 3.5.11 (unfixed + closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) firstname, (2) lastname, (3) website, (4) aim, (5) yahoo, (6) jabber, (7) about, (8) pass1, and (9) pass2 paramet...

Affected:
up to 3.5.11
Fix:
No patched version reported
Disclosed:
Dec 4, 2010

CVE-2010-4402 on NVD →

Register Plus [register-plus] <= 3.5.11 (unfixed + closed)

unknown

[en] The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

Affected:
up to 3.5.11
Fix:
No patched version reported
Disclosed:
Dec 4, 2010

CVE-2010-4403 on NVD →

Register Plus <= 3.5.11 - Stored Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.11 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) firstname, (2) lastname, (3) website, (4) aim, (5) yahoo, (6) jabber, (7) about, (8) pass1, and (9) pass2 parameters...

CVSS:
7.2
Affected:
up to 3.5.11
Fix:
No patched version reported
Disclosed:
Nov 24, 2010

CVE-2010-4402 on NVD →

Register Plus <= 3.5.11 - Sensitive Information Disclosure

medium

The Register Plus plugin 3.5.11 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

CVSS:
5.3
Affected:
up to 3.5.11
Fix:
No patched version reported
Disclosed:
Nov 24, 2010

CVE-2010-4403 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database