Archive for November, 2008

WordPress 2.6.2 Snoopy Vulnerability

WordPress announced the following vulnerability in WordPress 2.6.2:

A vulnerability in the Snoopy library was announced today.  WordPress uses Snoopy to fetch the feeds shown in the Dashboard. Although this seems to be a low risk vulnerability for WordPress users, we wanted to get an update out immediately. 2.6.3 is available for download right now. If [...]


st_newsletter SQL Injection

The st_newsletter Plugin is once again vulnerable to SQL Injection.

The hole is located within the page stnl_iframe.php, the parameter newsletter is missing correct sanitisation and so the plugin is prone to this attack. Currently we’re not aware about any fixes, users should disable the Plugin in the meantime, or should fix the problem their self. [...]


Multiple vulnerabilities in WP Comment Remix 1.4.3

A number of vulnerabilities have been discovered in the WP Comment Remix 1.4.3 plugin.

The following is a short overview of the vulnerabilities discovered:

SQL Injection: caused by unsanitized variable “p” in the ajax_comments.php file.
Cross Site Scripting: This affects authenticated and unauthenticated users.
Cross Site Request Forgery: the form generated through wpcr_do_options_page lacks the WordPress wp_nonce security function.

These [...]