RSS   Vulnerabilities for 'Optiontree'   RSS

2019-08-22
 
CVE-2019-15321

CWE-74
 

 
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.

 
 
CVE-2019-15320

CWE-74
 

 
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.

 
 
CVE-2019-15319

CWE-74
 

 
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.

 
2019-08-20
 
CVE-2016-10895

CWE-79
 

 
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.

 
 
CVE-2015-9320

CWE-79
 

 
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.

 


Copyright 2024, cxsecurity.com

 

Back to Top