plugin

Wordpress Whois Search Vulnerabilities

5 known security issues reported for the Wordpress Whois Search WordPress plugin. Most recent disclosed May 15, 2015.

2 medium

Running Wordpress Whois Search on your site? Check whether your installed version is affected.

Scan your site free

WHOIS [wordpress-whois-search] < 1.4.3 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
May 15, 2015

WHOIS <= 1.4.2.2 - Reflected Cross Site Scripting

medium

Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.

CVSS:
6.1
Affected:
up to 1.4.2.2
Fixed in:
1.4.2.3
Disclosed:
Aug 1, 2014

CVE-2011-5194 on NVD →

WHOIS <= 1.4.2.4 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.

CVSS:
6.1
Affected:
up to 1.4.2.4
Fix:
No patched version reported
Disclosed:
Sep 23, 2012

CVE-2011-5193 on NVD →

WHOIS [wordpress-whois-search] <= 1.4.2.4 (unfixed + closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to index.php, a different vulnerability than CVE-2011-5194.

Affected:
up to 1.4.2.4
Fix:
No patched version reported
Disclosed:
Sep 23, 2012

CVE-2011-5193 on NVD →

WHOIS [wordpress-whois-search] < 1.4.2.3 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.

Affected:
up to 1.4.2.3
Fixed in:
1.4.2.3
Disclosed:
Sep 23, 2012

CVE-2011-5194 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database