• Resolved suite_xss

    (@suite_xss)


    found such vulnerability result working wpscan:
    [!] Title: WP Photo Album Plus <= 4.1.1 – SQL Injection
    [!] Title: WP Photo Album Plus <= 4.8.12 – wp-photo-album-plus.php wppa-searchstring XSS
    [!] Title: WP Photo Album Plus – Full Path Disclosure
    [!] Title: WP Photo Album Plus – index.php wppa-tag Parameter XSS
    [!] Title: WP Photo Album Plus – “commentid” Cross-Site Scripting
    [!] Title: WP Photo Album Plus – wp-admin/admin.php edit_id Parameter XSS
    [!] Title: WP Photo Album Plus 5.4.5 – 5.4.8 Stored XSS
    [!] Title: WP Photo Album Plus 5.4.4 & 5.4.3 Cross-Site Scripting (XSS)

    https://wordpress.org/plugins/wp-easy-gallery/

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘xss vulnerability plugin’ is closed to new replies.