A vulnerability classified as problematic was found in WPGraphQL Plugin 0.2.3 on WordPress. Impacted is an unknown function of the component Query Handler. Such manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2019-9880. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability described as critical has been identified in Wise Chat Plugin up to 2.6 on WordPress. This vulnerability affects unknown code of the file rendering/filters/post/WiseChatLinksPostFilter.php. The manipulation results in open redirect.
This vulnerability is cataloged as CVE-2019-6780. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as problematic, has been found in WordPress Post Comment 0.2.3. The affected element is an unknown function of the component Comments. Performing manipulation as part of Comment results in missing authentication.
This vulnerability was named CVE-2019-9881. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as problematic, was found in WebAppick WooCommerce Product Feed up to 2.2.18 on WordPress. This affects an unknown part of the file admin/partials/woo-feed-manage-list.php:63 of the component Editing Theme File Handler. Executing manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2019-1010124. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability marked as problematic has been reported in cosenary Instagram-PHP-API up to 4.9.32 on WordPress. This vulnerability affects unknown code of the file example/success.php. Performing manipulation of the argument error_description as part of Parameter results in cross site scripting.
This vulnerability was named CVE-2019-14470. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in Simple Membership Plugin up to 3.8.4 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Bulk Operation Section. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2019-14328. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, was found in photo-gallery Plugin up to 1.5.34 on WordPress. This affects an unknown function of the file admin/controllers/Albumsgalleries.php. The manipulation of the argument album_id as part of Parameter results in sql injection.
This vulnerability is reported as CVE-2019-16119. The attack can be launched remotely. Moreover, an exploit is present.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in photo-gallery Plugin up to 1.5.34 on WordPress. The impacted element is an unknown function of the file admin/controllers/Options.php. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2019-16118. The attack can be initiated remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
Trend™ Research analyzed source binaries from the latest activity from notorious LockBit ransomware with their 5.0 version that exhibits advanced obfuscation, anti-analysis techniques, and seamless cross-platform capabilities for Windows, Linux, and ESXi systems.