plugin

Wp Symposium Vulnerabilities

32 known security issues reported for the Wp Symposium WordPress plugin. Most recent disclosed Sep 25, 2019.

4 critical 3 high 5 medium

Running Wp Symposium on your site? Check whether your installed version is affected.

Scan your site free

WP Symposium [wp-symposium] < 15.9 (closed)

unknown

[en] The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.

Affected:
up to 15.9
Fixed in:
15.9
Disclosed:
Sep 25, 2019

CVE-2015-9414 on NVD →

WP Symposium <= 15.8.1 - Reflected Cross-Site Scripting

medium

The WP Symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.

CVSS:
6.1
Affected:
up to 15.8.1
Fixed in:
15.9
Disclosed:
Sep 6, 2015

CVE-2015-9414 on NVD →

WP Symposium [wp-symposium] < 15.8 (closed)

unknown

[en] SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.

Affected:
up to 15.8
Fixed in:
15.8
Disclosed:
Aug 19, 2015

CVE-2015-6522 on NVD →

WP Symposium [wp-symposium] < 15.2 (closed)

unknown

Because of this vulnerability an attacker can extract information from the database. Upgrade to version 15.8.

Affected:
up to 15.2
Fixed in:
15.2
Disclosed:
Aug 18, 2015

WP Symposium < 15.8 - Blind SQL Injection

high

The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already...

CVSS:
7.2
Affected:
up to 15.8
Fixed in:
15.8
Disclosed:
Aug 10, 2015

WP Symposium [wp-symposium] < 15.8

unknown

The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already...

Affected:
up to 15.8
Fixed in:
15.8
Disclosed:
Aug 10, 2015

WP Symposium <= 15.8 - Unauthenticated SQL Injection

critical

SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.

CVSS:
9.8
Affected:
up to 15.8
Fixed in:
15.8
Disclosed:
Aug 9, 2015

CVE-2015-6522 on NVD →

WP Symposium [wp-symposium] < 15.4 (closed)

unknown

This WordPress Symposium plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Related records: http://db.threatpress.com/vulnerability/symposium-/wordpress-wp-symposium-plugi...

Affected:
up to 15.4
Fixed in:
15.4
Disclosed:
May 21, 2015

WP Symposium [wp-symposium] < 15.4 (closed)

unknown

[en] SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.

Affected:
up to 15.4
Fixed in:
15.4
Disclosed:
May 15, 2015

CVE-2015-3325 on NVD →

WP Symposium < 15.4 - SQL Injection

medium

SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.

CVSS:
5.3
Affected:
up to 15.4
Fixed in:
15.4
Disclosed:
Apr 14, 2015

CVE-2015-3325 on NVD →

WP Symposium [wp-symposium] < 15.1

unknown

[en] Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in server/php/.

Affected:
up to 15.1
Fixed in:
15.1
Disclosed:
Jan 13, 2015

CVE-2014-10021 on NVD →

WP Symposium [wp-symposium] < 14.11 (closed)

unknown

[en] SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.

Affected:
up to 14.11
Fixed in:
14.11
Disclosed:
Dec 24, 2014

CVE-2014-8810 on NVD →

WP Symposium [wp-symposium] < 14.11 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter in an addComment action to ajax/profile_functions.php, (2) compose_text parameter in a sendMail action to ajax/mail_func...

Affected:
up to 14.11
Fixed in:
14.11
Disclosed:
Dec 24, 2014

CVE-2014-8809 on NVD →

WP Symposium <= 14.11 - Arbitrary File Upload

critical

The WP Symposium plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the UploadHandler.php file in versions up to, and including, 14.11. This makes it possible for attackers to upload arbitrary files on the affected sites server which may make remote code execution possib...

CVSS:
9.8
Affected:
up to 14.11
Fixed in:
15.1
Disclosed:
Dec 11, 2014

CVE-2014-10021 on NVD →

WP Symposium < 14.11 - Authenticated SQL Injection

critical

SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.

CVSS:
9.9
Affected:
up to 14.11
Fixed in:
14.11
Disclosed:
Nov 26, 2014

CVE-2014-8810 on NVD →

WP Symposium <= 14.10 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the WP Symposium plugin before 14.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter in an addComment action to ajax/profile_functions.php, (2) compose_text parameter in a sendMail action to ajax/mail_functions...

CVSS:
6.1
Affected:
up to 14.10
Fixed in:
14.11
Disclosed:
Nov 26, 2014

CVE-2014-8809 on NVD →

WP Symposium <= 12.11 - SQL Injections

critical

The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

CVSS:
9.8
Affected:
up to 12.11
Fixed in:
12.12
Disclosed:
Aug 1, 2014

WP Symposium < 13.04 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the u parameter.

CVSS:
7.1
Affected:
up to 13.04
Fixed in:
13.04
Disclosed:
Aug 1, 2014

CVE-2013-2695 on NVD →

WP Symposium <= 13.04 - Open Redirection

medium

Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.

CVSS:
6.1
Affected:
up to 13.04
Fixed in:
13.05
Disclosed:
Aug 1, 2014

CVE-2013-2694 on NVD →

WP Symposium <= 11.11.26 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.

CVSS:
6.1
Affected:
up to 11.11.26
Fixed in:
11.12.08
Disclosed:
Aug 1, 2014

CVE-2011-3841 on NVD →

WP Symposium [wp-symposium] < 12.12 (closed)

unknown

The WP Symposium plugin for WordPress is vulnerable to various SQL Injections in versions up to, and including, 12.09 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL q...

Affected:
up to 12.12
Fixed in:
12.12
Disclosed:
Aug 1, 2014

WP Symposium [wp-symposium] < 13.05 (closed)

unknown

[en] Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.

Affected:
up to 13.05
Fixed in:
13.05
Disclosed:
Mar 28, 2014

CVE-2013-2694 on NVD →

WP Symposium [wp-symposium] < 13.04 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the u parameter.

Affected:
up to 13.04
Fixed in:
13.04
Disclosed:
Mar 28, 2014

CVE-2013-2695 on NVD →

WP Symposium [wp-symposium] < 11.12.24 (closed)

unknown

[en] Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via...

Affected:
up to 11.12.24
Fixed in:
11.12.24
Disclosed:
Jan 4, 2012

CVE-2011-5051 on NVD →

WP Symposium < 11.12.24 - Arbitrary File Upload

high

Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a dir...

CVSS:
8.8
Affected:
up to 11.12.24
Fixed in:
11.12.24
Disclosed:
Dec 28, 2011

CVE-2011-5051 on NVD →

WP Symposium [wp-symposium] < 11.12.08 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.

Affected:
up to 11.12.08
Fixed in:
11.12.08
Disclosed:
Dec 27, 2011

CVE-2011-3841 on NVD →

WP Symposium [wp-symposium] < 0.65 (closed)

unknown

This WordPress Symposium plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 0.65
Fixed in:
0.65
Disclosed:
Aug 17, 2011

WP Symposium [wp-symposium] < 15.8 (closed)

unknown

The wp-symposium WordPress plugin was affected by a Blind SQL Injection security vulnerability.

Affected:
up to 15.8
Fixed in:
15.8

WP Symposium [wp-symposium] < 11.08.18 (closed)

unknown

The wp-symposium WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 11.08.18
Fixed in:
11.08.18

WP Symposium [wp-symposium] < 12.07.01 (closed)

unknown

The wp-symposium WordPress plugin was affected by a Multiple SQL Injections security vulnerability.

Affected:
up to 12.07.01
Fixed in:
12.07.01

WP Symposium [wp-symposium] <= 12.07.07 (unfixed + closed)

unknown

The wp-symposium WordPress plugin was affected by an Authentication Bypass security vulnerability.

Affected:
up to 12.07.07
Fix:
No patched version reported

WP Symposium [wp-symposium] < 12.12 (closed)

unknown

The wp-symposium WordPress plugin was affected by a Multiple SQL Injections security vulnerability.

Affected:
up to 12.12
Fixed in:
12.12

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database