Shawn DeWolfe Consulting
  • Services
    • WordPress Web Design
    • WordPress Support
    • WordPress Hosting
    • Performance Boost
    • Writing
  • AI Agency
  • Web Development
        • Plugin Development

          We do WordPress plugins. Read More
        • Pixel to Viewport CSS

          Convert CSS. Read More
        • Integrations

          We build integreations with other systems via API calls and API creation. Read More
  • Portfolio
    • Portfolio
    • Web Development
    • The Really Old Portfolio
  • About
    • Blog
    • Victoria Web Designers
    • Partnerships
    • Hey Shawn!
    • Interesting Finds
    • Cool Coding Tricks
  • Contact
Select Page
Contact Form Clean and Simple <= 4.7.0 – Authenticated Stored XSS

Contact Form Clean and Simple <= 4.7.0 – Authenticated Stored XSS

Jan 22, 2020 | WordPress Vulnerabilities

DescriptionContact Form Clean and Simple is vulnerable to Authenticated stored XSS. When a user has admin capabilities, malicious code can be submitted through the plugin’s options. This code will then be executed on every page with the contact form on the...

Batch-Move Posts <= 1.5 – Broken Authentication leading to Unauthenticated Stored XSS

Jan 19, 2020 | WordPress Vulnerabilities

Proof of Concept Vulnerable code is from like 68 to 84. The code gets the value of option `bm_row_amount` from database and matches it with the GET request `row_amount`. If they do not match then it updates the option `bm_row_amount` with the provided GET value. If...

Marketo Forms and Tracking <= 1.0.2 – CSRF to XSS

Jan 18, 2020 | WordPress Vulnerabilities

<html> <form action=”https://[WP]/wp-admin/admin.php?page=marketo_fat” method=”POST” id=”csrf”> <input type=”text” name=”marketo_save” value=”true”> <input...

InfiniteWP Client < 1.9.4.5 – Authentication Bypass

Jan 17, 2020 | WordPress Vulnerabilities

Proof of Concept It is possible to login as any administrator on the site due to logical mistakes in the code. The issue resides in the function iwp_mmb_set_request which is located in the init.php file. This checks if the request_params array of the core class is not...

LearnDash < 3.1.2 – Reflected Cross Site Scripting (XSS) issue on the [ld_profile] search field.

Jan 16, 2020 | WordPress Vulnerabilities

DescriptionReflected Cross Site Scripting (XSS) issue on the [ld_profile] search field. First reported to Learndash on January 14, 2020, and update 3.1.2 to fix it was released same day. This report is based on an email LearnDash sent out to their users on January 14,...
« Older Entries
Next Entries »

Other Links

  • Request A Quote
  • Website Design
  • WordPress Hosting
  • WordPress Support
  • Performance Boosting
  • Other Services
  • Domain Name Registration
  • Counsellor Web Design Suite
  • Tourism Web Design Suite
  • More on Managed WordPress

Our Policies

  • Our Policies and Practices
  • Market Competition Policy
  • Privacy Policy
Request A Quote Contact us Phone: 1-844-493-2321 Web321: WordPress Design in Victoria
  • Facebook
  • Instagram
  • X (Twitter)
  • RSS

Designed by Elegant Themes | Powered by WordPress