WHOIS [wordpress-whois-search] < 1.4.3 (closed)
unknownBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- May 15, 2015
plugin
5 known security issues reported for the Wordpress Whois Search WordPress plugin. Most recent disclosed May 15, 2015.
Running Wordpress Whois Search on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.
[en] Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.
[en] Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free