🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION‼ New - CVE-2015-9390

The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9389

The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9388

The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9387

The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9386

The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9385

The quotes-and-tips plugin before 1.20 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9384

The relevant plugin before 1.0.8 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9408

The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9407

The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9405

The wp-piwik plugin before 1.0.5 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9404

The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9403

The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9402

The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9401

The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9400

The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9399

The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9398

The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9397

The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9396

The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file= XSS.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9395

The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

📖 Read

via "National Vulnerability Database".
ATENTION‼ New - CVE-2015-9394

The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

📖 Read

via "National Vulnerability Database".