Web Instant Messenger [web-instant-messenger] <= 1.1.2 (unfixed + closed)
unknown
Unauthenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze (Ex.Mi) in WordPress Web Instant Messenger plugin (versions <= 1.1.2).
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 20, 2020
Web Instant Messenger <= 1.1.2 and LocalWeb In One <= 1.6.4 - Stored Cross-Site Scripting
high
The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 (NOTE: Web Instant Messenger's latest version 1.1.2 is unpatched) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- CVSS:
- 7.2
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 12, 2020
Web Instant Messenger [web-instant-messenger] <= 1.1.2 (unfixed + closed)
unknown
The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.4 (NOTE: Web Instant Messenger's latest version 1.1.2 is unpatched) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 12, 2020
Web Instant Messenger [web-instant-messenger] <= 1.1.2 (unfixed + closed)
unknown
An Unauthenticated Stored XSS vulnerability was discovered in the LocalWeb All In One plugin v1.6.3 for WordPress.
There is an older version of this plugin called Web Instant Messenger, latest version is v1.1.1.
The specificity of this plugin is that it interacts with the remote host www.localweb.it, so the paylo...
- Affected:
- up to 1.1.2
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database