The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
View Full Alert
Related Posts
CVE-2015-9467 (broken_link_manager)The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. View Full Alert
CVE-2015-9453 (broken_link_manager)The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist. View Full Alert
CVE-2015-9297The events-manager plugin before 5.6 for WordPress has XSS. View Full Alert