VYPR

Landing Pages

by Landing Pages Project

CVEs (2)

  • CVE-2015-4065May 27, 2015
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.

  • CVE-2015-4064May 27, 2015
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.