(#Several vulnerabilities have been identified in third-party plugins for WordPress:#- Olimometer: SQL injection in the "olimometer_id" parameter of the "plugins/olimometer/thermometer.php" page##- Wp-D3: cross-site request forgery##- FancyBox: full path disclosure in the "plugins/fancybox-for-wordpress/lib/admin-head.php" page##- Image Gallery: stored cross-site scripting in the source URL via the "sl_url11" POST parameter.##Proof of concepts are available.)