Wordpress Multiple Third Party Plugins Multiple Vulnerabilities
Description
(#Multiple vulnerabilities have been identified in third-party plugins for Wordpress:#- MailPoet Newsletters: cross-site scripting via the "wysija-key" parameter of the "?wysija-page=1&controller=confirm" web page##- Booking Calendar Contact Form: SQL injection in the "admin-ajax.php?action=cpabc_appointments_calendar_update" web page##- Booking Calendar Contact Form: multiple stored cross-site scripting##- Appointment Booking Calendar: SQL injection##- IMPress Listings: cross-site scripting##- Comment Rating: cross-site scripting via the "tab" parameter of the "wpb_plugin_admin_page.php" web page##- Invoice: information disclosure, unauthorized updating of meta data and privilege escalation##- User Meta Manager: information disclosure, privilege escalation and blind SQL injection##- Huge It Image Gallery: multiple cross-site scripting via POST parameters "linkbutton" and "thumbtext" of the "wp-admin/admin-ajax.php?action=huge_it_video_gallery_ajax" web page##- Formidable Forms: blind SQL injection (CVE-2014-9309)##- Connections: cross-site scripting located in the search field (CVE-2016-0770)##- eshop: cross-site scripting (CVE-2016-0765) et blind SQL injection (CVE-2016-0769)##- Simple Add Pages Or Posts: cross-site request forgery.)