s2member Secure File Browser [s2member-secure-file-browser] < 0.4.17
unknownBecause of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.
- Affected:
- up to 0.4.17
- Fixed in:
- 0.4.17
- Disclosed:
- May 14, 2015
plugin
3 known security issues reported for the S2Member Secure File Browser WordPress plugin. Most recent disclosed May 14, 2015.
Running S2Member Secure File Browser on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free