plugin

Simple Security Vulnerabilities

2 known security issues reported for the Simple Security WordPress plugin. Most recent disclosed Jan 15, 2015.

1 medium

Running Simple Security on your site? Check whether your installed version is affected.

Scan your site free

Simple Security [simple-security] < 1.1.6

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the access_log page to wp-admin/users.php or (2) simple_security_ip_blacklist[] parame...

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Jan 15, 2015

CVE-2014-9570 on NVD →

Simple Security <= 1.1.5 - Authenticated Stored Cross-Site Scripting

medium

The Simple Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'datefilter' parameter found on the access_log page to wp-admin/users.php and the 'simple_security_ip_blacklist[]' parameter found in the add_blacklist_ip action on the ip_blacklist page to wp-admin/users.php in versions up to...

CVSS:
4.8
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Jan 14, 2015

CVE-2014-9570 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database