YAWPP (Yet Another WordPress Petition Plugin) <= 1.2.2 - Cross-Site Scripting
medium
The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2015
CVE-2015-9391 on NVD →
YAWPP (Yet Another WordPress Petition Plugin) <= 1.2.1 - Authenticated SQL Injection
high
Multiple SQL injection vulnerabilities in the yawpp plugin 1.2.1 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) admin_functions.php or (2) admin_update.php, as demonstrated by the id parameter in the update action to wp-admin/admin...
- CVSS:
- 8.8
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- May 28, 2014
CVE-2014-5182 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database