The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_…
The relevant plugin before 1.0.8 for WordPress has XSS.
The quotes-and-tips plugin before 1.20 for WordPress has XSS.
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
The updater plugin before 1.35 for WordPress has multiple XSS issues.
The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.
The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.
The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.
The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.
The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
The visitors-online plugin before 0.4 for WordPress has SQL injection.
The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.
The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.