Jeffro2pt0 at WeblogToolsCollection has reported two new vulnerabilities that have recently been found in WordPress plugins:
Today, we have a moderately critical SQL Injection Vulnerability that was discovered by HouSSaMix in the “WP-Cal” plugin version 0.x for WordPress.
A person who goes by the handle “enter_the_dragon” has discovered a vulnerability within the Adserve Plugin version 0.2 for WordPress.
More info at WeblogToolsCollection website.
“found in WordPress:” should probably be “found in WordPress plugins:” or the like.
Thanks for reporting it Lloyd.