Wordpress Multiple Third Party Plugins Multiple Vulnerabilities
Description
Several vulnerabilities have been identified in plugins for WordPress:
- Responsive Thumbnail Slider: arbitrary file upload
- Responsive Thumbnail Slider: cross-site scripting in "wp-responsive-images-thumbnail-slider.php" source file
- Subscribe Comments File Read: tdirectory traversal via "options-general.php" source file
- All-in-One Migration Export: information disclosure via "wordpress_url_admin_ajax" cgi file
- Mobile Pack Information: information disclosure via "content.php" source file
- Captain Slider: cross-site scripting via slider management section
- Job Manager: information disclosure via a brute force over insecure direct object reference (CVE-2015-6668)
- SourceAFRICA: cross-site scripting via "window.php" source file
- Testimonial Slider: cross-site scripting
- Watu PRO: cross-site request forgery via "admin.php" source file
- BJ Lazy Load: arbitrary file upload
- WPML: cross-site scripting via "Accept-Language" header.
Proofs of concept are available.
Exploitation code are available for these vulnerabilities under metasploit framework.