Aerosol Posted December 13, 2014 Report Posted December 13, 2014 WordPress Our Team Showcase 1.2 CSRF / XSSWordPress IP Ban 1.2.3 CSRF / XSSWordPress WP-ViperGB 1.3.10 CSRF / XSSWordPress Simple Visitor Stat Cross Site ScriptingWordPress Simple Sticky Footer 1.3.2 CSRF / XSSWordPress Sliding Recent Posts 1.0 CSRF / XSSWordPress WP Symposium 14.11 Shell UploadWordPress Facebook Like Box 2.8.2 CSRF / XSSWordPress Lightbox Photo Gallery 1.0 CSRF / XSSWordPress WP-FB-AutoConnect 4.0.5 CSRF / XSSWordPress Sliding Social Icons 1.61 CSRF / XSSWordPress Timed Popup 1.3 CSRF / XSSWordPress WP Construction Mode 1.91 XSS Quote
Aerosol Posted December 16, 2014 Author Report Posted December 16, 2014 Wordpress Download Manager (download-manager) Unauthenticated File UploadWordPress iTwitter WP 0.04 CSRF / XSSWordPress twitterDash 2.1 CSRF / XSSWordPress DandyID Services ID 1.5.9 CSRF / XSSWordPress SPNbabble 1.4.1 CSRF / XSSWordPress Download Manager 2.7.4 Remote Command ExecutionWordPress wpCommentTwit 0.5 CSRF / XSSWordPress yURL ReTwitt WP 1.4 CSRF / XSSMikiurl WordPress Eklentisi 2.0 CSRF / XSSWordPress O2Tweet 0.0.4 CSRF / XSS Quote
Aerosol Posted December 19, 2014 Author Report Posted December 19, 2014 WordPress iTwitter 0.04 Cross Site Request Forgery / Cross Site ScriptingWordPress PictoBrowser 0.3.1 CSRF / XSSWordPress Twitter 0.7 CSRF / XSSWordPress PWG Random 1.11 CSRF / XSSWordPress gSlideShow 0.1 CSRF / XSSWordPress SimpleFlickr 3.0.3 CSRF / XSSWordPress twimp-wp Cross Site Request Forgery / Cross Site ScriptingWordPress Simplelife 1.2 CSRF / XSS ? Packet StormWordPress Twitter LiveBlog 1.1.2 CSRF / XSSWordPress TweetScribe 1.1 CSRF / XSSWordPress WP Limit Posts Automatically 0.7 CSRF / XSSWordPress WP Unique Article Header Image 1.0 CSRF / XSS Quote
Aerosol Posted January 30, 2015 Author Report Posted January 30, 2015 WordPress Photo Gallery 1.2.8 Cross Site ScriptingWordPress Photo Gallery 1.2.8 SQL InjectionWordPress Geo Mashup 1.8.2 Cross Site Scripting Quote
Aerosol Posted February 5, 2015 Author Report Posted February 5, 2015 (edited) WordPress Platform Theme Remote Code ExecutionWordPress Pixabay Images PHP Code Upload Edited February 20, 2015 by Aerosol Quote
Aerosol Posted February 11, 2015 Author Report Posted February 11, 2015 (edited) WordPress WP EasyCart Unrestricted File UploadWordPress Cross Slide 2.0.5 Cross Site Request Forgery / Cross Site ScriptingWordPress Mobile Domain 1.5.2 Cross Site Request Forgery / Cross Site ScriptingWordPress Spider Facebook 1.0.10 Cross Site ScriptingWordPress Redirection Page 1.2 CSRF / XSSWordPress Google Doc Embedder 2.5.18 Cross Site ScriptingWordPress Acobot Live Chat And Contact Form 2.0 CSRF / XSSWordPress Contact Form DB 2.8.26 Cross Site ScriptingWordPress Cart66 Lite 1.5.4 Cross Site ScriptingWordPress WPLMS 1.8.4.1 Privilege Escalation Edited February 11, 2015 by Aerosol Quote
Aerosol Posted February 14, 2015 Author Report Posted February 14, 2015 (edited) WordPress Easing Slider 2.2.0.6 Cross Site ScriptingWordPress Ninja Forms 2.8.8 Cross Site ScriptingWordPress Video Gallery 2.7 SQL InjectionWordPress Survey And Poll 1.1.7 Blind SQL InjectionWordPress Photo Gallery 1.2.5 Unrestricted File UploadWordPress Fusion 1.9.1 Arbitrary File UploadWordPress Image Metadata Cruncher Cross Site ScriptingWordPress Image Metadata Cruncher CSRF / XSSWordPress Duplicator 0.5.8 Privilege Escalation Edited February 18, 2015 by Aerosol Quote
Aerosol Posted March 2, 2015 Author Report Posted March 2, 2015 (edited) WordPress Calculated Fields Form 1.0.10 SQL InjectionWordPress WP All 3.2.3 Shell UploadWordPress Photocrati Theme 4.x.x SQL InjectionWordPress Newsletter 2.6.x / 2.5.x Open RedirectWordPress Max Banner Ads 1.9 Cross Site ScriptingWordPress Ya'aburnee / Dignitas Privilege EscalationWordPress Contact Form DB 2.8.29 Cross Site Request Forgery Edited March 5, 2015 by Aerosol Quote
Aerosol Posted March 24, 2015 Author Report Posted March 24, 2015 WordPress AB Google Map Travel CSRF / XSSWordPress Ajax Search Pro Remote Code ExecutionWordPress InBoundio Marketing Shell UploadWordPress MP3-Jplayer 2.1 Local File Disclosure Quote