WP-Cumulus [wp-cumulus] < 1.23 (closed)
unknownBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected:
- up to 1.23
- Fixed in:
- 1.23
- Disclosed:
- May 15, 2015
plugin
10 known security issues reported for the Wp Cumulus WordPress plugin. Most recent disclosed May 15, 2015.
Running Wp Cumulus on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
The WP-Cumulus plugin for WordPress is vulnerable to Cross-Site Scripting via the 'xmlpath' parameter in versions up to, and including, 1.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.
The WP-Cumulus plugin for WordPress is vulnerable to Cross-Site Scripting via the 'xmlpath' parameter in versions up to, and including, 1.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulne...
[en] Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS)...
[en] Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[en] WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.
WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.
Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
The wp-cumulus WordPress plugin was affected by a Cross Site Scripting Vulnerabily security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free