oss-sec mailing list archives

Multiple XSS vulnerabilities affecting five WordPress Plugins


From: Summer of Pwnage <lists () securify nl>
Date: Sat, 19 Nov 2016 11:50:40 +0100

Please see attached advisories for more information. These issues were found during Summer of Pwnage (https://sumofpwn.nl), a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way.






Attachment: cross_site_scripting_in_all_in_one_wp_security___firewall_wordpress_plugin.txt
Description:

Attachment: cross_site_scripting_in_check_email_wordpress_plugin.txt
Description:

Attachment: cross_site_scripting_in_huge_it_portfolio_gallery_wordpress_plugin.txt
Description:

Attachment: persistent_cross_site_scripting_in_instagram_feed_plugin_via_csrf.txt
Description:

Attachment: stored_cross_site_scripting_in_wp_canvas___shortcodes_wordpress_plugin.txt
Description:


Current thread: