oss-sec mailing list archives

Multiple Cross-Site Scripting vulnerabilities affecting seven WordPress Plugins


From: Summer of Pwnage <lists () securify nl>
Date: Thu, 4 Aug 2016 19:40:14 +0200

Please see attached advisories for more information. These issues were found during Summer of Pwnage (https://sumofpwn.nl), a Dutch community project. Its goal is to contribute to the security of popular, widely used OSS projects in a fun and educational way.


Attachment: cross_site_scripting_in_activity_log_wordpress_plugin.txt
Description:

Attachment: cross_site_scripting_in_count_per_day_wordpress_plugin.txt
Description:

Attachment: cross_site_scripting_in_formbuilder_wordpress_plugin.txt
Description:

Attachment: cross_site_scripting_in_wordpress_landing_pages_plugin.txt
Description:

Attachment: cross_site_scripting_vulnerability_in_events_made_easy_wordpress_plugin.txt
Description:

Attachment: cross_site_scripting_vulnerability_in_search_function_activity_log_wordpress_plugin.txt
Description:

Attachment: stored_cross_site_scripting_vulnerability_in_count_per_day_wordpress_plugin.txt
Description:


Current thread: