plugin

Wp Cumulus Vulnerabilities

10 known security issues reported for the Wp Cumulus WordPress plugin. Most recent disclosed May 15, 2015.

1 high 3 medium

Running Wp Cumulus on your site? Check whether your installed version is affected.

Scan your site free

WP-Cumulus [wp-cumulus] < 1.23 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.23
Fixed in:
1.23
Disclosed:
May 15, 2015

WP-Cumulus <= 1.22 - Cross-Site Scripting via xmlpath

medium

The WP-Cumulus plugin for WordPress is vulnerable to Cross-Site Scripting via the 'xmlpath' parameter in versions up to, and including, 1.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.22
Fixed in:
1.23
Disclosed:
Nov 20, 2011

WP-Cumulus [wp-cumulus] < 1.23 (closed)

unknown

The WP-Cumulus plugin for WordPress is vulnerable to Cross-Site Scripting via the 'xmlpath' parameter in versions up to, and including, 1.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.23
Fixed in:
1.23
Disclosed:
Nov 20, 2011

WP-Cumulus <= 1.22 - Cross-Site Scripting via tagcloud

medium

Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulne...

CVSS:
6.1
Affected:
up to 1.22
Fixed in:
1.23
Disclosed:
Dec 2, 2009

CVE-2009-4168 on NVD →

WP-Cumulus [wp-cumulus] < 1.23 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS)...

Affected:
up to 1.23
Fixed in:
1.23
Disclosed:
Dec 2, 2009

CVE-2009-4168 on NVD →

WP-Cumulus [wp-cumulus] < 1.22 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 1.22
Fixed in:
1.22
Disclosed:
Dec 2, 2009

CVE-2009-4169 on NVD →

WP-Cumulus [wp-cumulus] < 1.23 (closed)

unknown

[en] WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.

Affected:
up to 1.23
Fixed in:
1.23
Disclosed:
Dec 2, 2009

CVE-2009-4170 on NVD →

WP-Cumulus <= 1.20 - Sensitive Information Exposure

medium

WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.

CVSS:
5.3
Affected:
up to 1.20
Fixed in:
1.23
Disclosed:
Nov 25, 2009

CVE-2009-4170 on NVD →

WP Cumulus < 1.22 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
7.1
Affected:
up to 1.22
Fixed in:
1.22
Disclosed:
Sep 27, 2009

CVE-2009-4169 on NVD →

WP-Cumulus [wp-cumulus] < 1.23 (closed)

unknown

The wp-cumulus WordPress plugin was affected by a Cross Site Scripting Vulnerabily security vulnerability.

Affected:
up to 1.23
Fixed in:
1.23

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database