(#Several vulnerabilities have been identified in third-party plugins for WordPress:#- WP Google Maps: stored cross-site scripting in the "wpgmza_store_locator_query_string" parameter of the "wpGoogleMaps.php" script file#- WP Ninja Forms: arbitrary file upload#- WP-EMail: SQL injection and cross-site scripting#- W3 Total Cache: information disclosure and security bypass#- Video Gallery: cross-site scripting and cross-site request forgery#- Lightbox: cross-site scripting#- Check Email: cross-site scripting#- WP eCommerce: SQL injection in the "sessionid" parameter#- Imagely NextGen Gallery - CVE-2016-6565: remote file inclusion#- All in One WP Security and Firewall: cross-site scripting#- Post Grid : arbitrary file deletion#- Google Analytics Counter Tracker : PHP object injection##Proof of concepts are available.##An exploitation code is available on the metasploit framework for the WP Ninja Forms module vulnerability.)