This Metasploit module exploits an authenticated directory traversal vulnerability in WordPress Plugin "Subscribe to Comments" version 2.1.2, allowing to read arbitrary files with the web server privileges.
fd7b19a9193f7aff16d3b71d71eee92ef8df3e278021933d800166fd2f528d75
WordPress Tooltipy plugin version 5.0 suffers from a cross site request forgery vulnerability.
c8f3750df4042e50ce773fbee50cec7873f62c34d26909645eb06b443dfe7052
WordPress Tooltipy plugin version 5.0 suffers from a cross site scripting vulnerability.
6eb4e52fcad8f00b82c4a47e651cb7194795e04d338435768fede1fe9077fca4
Metronet Tag Manager version 1.2.7 suffers from a cross site request forgery vulnerability.
4ab4d2176f53eb69df95bbb67d0c117d46bdab059f7376224e9529ecaeee5ec1
WordPress WP ULike plugin versions 2.8.1 and 3.1 suffer from an arbitrary data deletion vulnerability.
60d548f9ac31206f6dce81a9bd584718eec670910c5bc25fa7aeb146d86335c1
WordPress WP ULike plugin versions 2.8.1 and 3.1 suffer from a persistent cross site scripting vulnerability.
80d7060c00ca4ddac7b6916ec8392a1db436aa0ccb9d5f13d711e383093b1282
WordPress WP User Groups plugin version 2.0.0 suffers from a cross site request forgery vulnerability.
509946df5bd9ecce73ceac8f4fc333c4607a97cee298af0243863dead17a7716
WordPress WP Image Zoom plugin version 1.23 suffers from a denial of service vulnerability.
c8f25d0b435ab4c7dcc42419ac30a803214cba1b96eb5f1582fbf7cae9794cb1
WordPress Rating-Widget: Star Review System plugin version 2.8.9 suffers from an information disclosure vulnerability.
6996d44e889c5267184b5c120e1c55d97a2ff86f9bc246ed1fa782b6c6a78622
WordPress Content Audit plugin version 1.9.1 suffers from cross site request forgery and cross site scripting vulnerabilities.
dc984adf5f9d9543aacd7fed916439032c04082b190d496601317b59fad3d41e
Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 suffers from a persistent cross site scripting vulnerability.
436fa0bce96b432cc53cebe95a1a22ae31fb0609f0f4a08f9049bd7a51546ec4
WordPress Stop User Enumeration plugin version 1.3.8 suffers from a user enumeration vulnerability.
b7513f284de1b5522ef7c496fd4c6816b69284ea65ff20882b3bb5824e1e4e39
WordPress YouTube Embed Plus plugin version 11.8.1 suffers from a cross site request forgery vulnerability.
6978786658c9e7e79af098ad01d5a2b6a44041145b418751a98e98150db7f01e
WordPress Download Manager plugin versions 2.9.46 and 2.9.51 suffer from a cross site scripting vulnerability.
9de753843f33ce3f2dc9d5d13e262f6df0bb99ce7db35001b0177d5ed23072d8
WordPress Photo Gallery plugin versions 1.3.34 and 1.3.42 suffer from a path traversal vulnerability.
2e48b2bcd6a9011319d2820c216c197e008cdd23983c64c58a88c29df02fc36b
WordPress Firewall 2 version 1.3 suffers from cross site request forgery and cross site scripting vulnerabilities.
e931376033f97633c8fcb5a60100c1bfabead9f74477b8421f59aa6b4043e110
Responsive Poll versions 1.6.4 and 1.7.4 suffer from cross site request forgery and cross site scripting vulnerabilities.
ee6234965da9f0f4d9be5eecc91280e2f8c402d7627fe1d94a5d6448edc5a9ea
WordPress Stop User Enumeration plugin version 1.3.4 fails to stop user enumeration.
a5b9ecefc46a9dc57fc49c4583f89b99ebc64da867181e4ef815252dc040302a
WordPress Image Slider plugin versions 1.1.41 and 1.1.89 suffer from an arbitrary file deletion vulnerability.
d26c0835b8209ca0f2b538837df8ceca4fa3b26c17c033bd4da15d6d4bce5a72
WordPress Copy-Me plugin version 1.0.0 suffers from a cross site request forgery vulnerability.
0f71f5e7759396da0da6cf867dfaa526d9638e8c6acf7187329c685417d8fdd3
WordPress Quiz and Survey Master versions 4.5.4 and 4.7.8 suffer from cross site request forgery and cross site scripting vulnerabilities.
f46a82fbc2630dc8ef0a1701356ad5a2f60798aabadbf007ed0cc9eebd4334d5
WordPress MailChimp versions 3.1.5 and 4.0.10 suffer from a cross site scripting vulnerability.
ff179074357ac7336249ba032d5f12b0766d960a4f96041e3a66d6151fb4c1a0
WordPress Multisite Post Duplicator version 0.9.5.1 suffers from a cross site request forgery vulnerability.
a48083336df703d960a3e51cefa17b950424b1a6e48bc9ebe6980313d31bba7f
WordPress Advanced Custom Fields: Table Field plugin version 1.1.12 suffers from a persistent cross site scripting vulnerability.
22e77075a340c777a01ecc58cf41ba5881366012a20be804f683d80e887132c8
Watu PRO Play version 1.9.2.1 suffers from a stored cross site scripting vulnerability.
162ad6b6b2124d6a4b68d4f59d55c906e0cedefe55ce2e38170f36bb61e258e0