SEO SearchTerms Tagging 2 <=1.535 - SQL Injection
high
The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF.
- CVSS:
- 7.2
- Affected:
- up to 1.535
- Fix:
- No patched version reported
- Disclosed:
- Jul 8, 2015
CVE-2015-9458 on NVD →
searchterms-tagging-2 <= 1.535 - Reflected Cross-Site Scripting
medium
The searchterms-tagging-2 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `count` parameter in versions up to, and including 1.535. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performin...
- CVSS:
- 6.1
- Affected:
- up to 1.535
- Fix:
- No patched version reported
- Disclosed:
- Jul 8, 2015
CVE-2015-9459 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database