Wordpress Multiple Third Party Plugins Cross-site Scripting Vulnerabilities
Description
(#Several cross-site scripting vulnerabilities were identified in third-party plugins for WordPress:#- indexisto: CVE-2016-77360#- whizz: plugin CVE-2016-77799#- anti-plagiarism: CVE-2016-77035#- page-layout-builder: CVE-2016-77503#- e-search: CVE-2016-77217#- parsi-font: 2016-77506#- defa-online-image-protector: CVE-2016-77193#- new-year-firework: CVE-2016-77475#- simpel-reserveren: CVE-2016-77628#- ajax-random-post: CVE-2016-77022#- admin-font-editor: CVE-2016-77009#- hdw-tube: CVE-2016-77337#- hero-maps-pro: CVE-2016-77341#- photoxhibit: CVE-2016-77517#- pondol-formmail: CVE-2016-77532#- heat-trackr: CVE-2016-77339#- tidio-form: CVE-2016-77726#- simplified-content: CVE-2016-77642#- infusioft: CVE-2016-77364##A remote attacker could exploit them in order to execute arbitrary JavaScript or HTML code by enticing their victim into following a specially formed link.##Proof of concepts are available.)