(#Several vulnerabilities have been identified in third-party plugins for WordPress:#- cmw-speakers: SQL injection in the "id" parameter of the "speaker_details.php" page#- 404 Redirection Manager: SQL injection#- Stop User Enumeration: cross-site scripting#- Direct Download for WooCommerce: local file inclusion allowing remote download from the server#- WangGuard: cross-site scripting.##Proofs of concept are available.)
Vulnerable Products
Vulnerable Software: WordPress (WordPress) -
Solution
Version 1.3.8 of plugin Stop User Enumeration fixes the vulnerability affecting it.