RSS   Vulnerabilities for 'Wpglobus'   RSS

2018-01-12
 
CVE-2018-5367

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.

 
 
CVE-2018-5366

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.

 
 
CVE-2018-5365

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php.

 
 
CVE-2018-5364

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php.

 
 
CVE-2018-5363

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php.

 
 
CVE-2018-5362

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.

 
 
CVE-2018-5361

CWE-79
 

 
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.

 


Copyright 2024, cxsecurity.com

 

Back to Top