Wordpress Multiple Third Party Plugins Multiple Vulnerabilities
Description
(#Multiple vulnerabilities have been identified in plugins for Wordpress:#- CVE-2015-7527: Cool Video Gallery: arbitrary command injection in the "cool-video-gallery/lib/core.php" page##- Auto ThickBox Plus: cross-site scripting in the "file" parameter of the "wp-content/plugins/auto-thickbox-plus/download.min.php" page##- CVE-2015-7517: Double Opt-In: SQL injection in the "includes/class-doifd-download.php" page##Proofs of concept are available)
Vulnerable Products
Vulnerable Software: WordPress (WordPress) -
Solution
Version 2.0.9 of Double Opt-In for Download fixes the vulnerability affecting it.