➠ SEO Redirection Plugin up to 6.3 on WordPress 301 Redirect cross site scripting
A vulnerability was found in SEO Redirection Plugin up to 6.3 on WordPress (WordPress Plugin) and classified as problematic. This issue affects an unknown function of the component 301 Redirect Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product....
Zur Startseite
➤ Ähnliche Beiträge für 'SEO Redirection Plugin up to 6.3 on WordPress 301 Redirect cross site scripting'
XSS in yoast form class
vom 2482.99 Punkte
Variables in form class is not properly escaped to prevent an XSS attack
This vulnerability affects the following application versions:
Yoast SEO 2.0
Yoast SEO 2.0.1
Yoast SEO 2.1
Comments on private posts could be leaked to other users
vom 2276.1 Punkte
Users who lack visibility to a post are also able to access or view the comments associated with it.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
Open redirect in wp_nonce_ays
vom 2060.71 Punkte
The WordPress HTTP referer is not properly validated when a user is redirected.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
Stored XSS and information exposure via wp-mail.php
vom 2053.85 Punkte
User authentication is not properly checked when the WordPress mail is run to prevent stored XSS. Additionally, adding email addresses from post-by-email logs are creating potential for information exposure vulnerability.
This vulnerability affects t
Stored XSS via comment editing
vom 2050.02 Punkte
Missing adequate checks during comment editing can lead to stored XSS attacks.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
Leak in content from multipart emails and reverting shared objects for current user
vom 2050.02 Punkte
Reset PHPMailer properties between use to prevent information disclosure and revert shared objects for the current user to also prevent information disclosure
This vulnerability affects the following application versions:
WordPress 3.6
CSRF in wp-trackback.php
vom 2050.02 Punkte
Missing authentication settings can lead to CSRF attacks
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
WordPress 3.7.
SQL injection within the link API
vom 1958.06 Punkte
The link API in the bookmark is not properly checked against an SQL injection.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
XSS vulnerability on the plugins screen
vom 1958.06 Punkte
The plugins screen is not properly escaped to prevent an XSS attack.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
WordPress 3.7.
Output escaping issue within the_meta()
vom 1958.06 Punkte
A variable in the_meta() function is not properly escaped to prevent an XSS attack.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1
WordPress 3.7
Cast user_id to int to prevent XSS
vom 1794.93 Punkte
Introducing type casting to avoid XSS.
This vulnerability affects the following application versions:
Yoast SEO 1.6.2
Yoast SEO 1.6.3
Yoast SEO 1.7
Yoast SEO 1.7.1
Object injection in some multisite installations
vom 1770.3 Punkte
The multisite installation of WordPress is not properly sanitized to prevent object injection via the upgrade process.
This vulnerability affects the following application versions:
WordPress 3.6
WordPress 3.6.1