Wordpress Multiple Third Party Plugins Vulnerabilities
Description
(#Several vulnerabilities have been identified in third-party plugins for Wordpress:#- Easyrotator: file manipulation in the "processuploadedzip()" function of the "/engine/main.php" page##- safe-editor: CSS/JS injection on the "wp_head" and "wp_footer" parameters of "index.php" page##- brafton: cross-site scripting in the GET "tab" parameter of the "BraftonAdminPage.php" page##- WP Fastest Cache: local file inclusion. An attacker could exploit it to steal or manipulate data##- Jetpack: stored cross-site scripting##- Polldaddy Polls & Ratings: stored cross-site scripting##Proof of concepts are available.)