Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-2700 1 Webmaster-source 1 Wp125 2025-04-12 N/A
Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that add or edit an ad via unspecified vectors.
CVE-2015-9398 1 Webmaster-source 1 Gocodes 2024-11-21 8.8 High
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.
CVE-2015-9397 1 Webmaster-source 1 Gocodes 2024-11-21 5.4 Medium
The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS.