Vulnerabilities > Ajaydsouza > Contextual Related Posts > 1.8.5

DATE CVE VULNERABILITY TITLE RISK
2014-06-02 CVE-2014-3937 SQL Injection vulnerability in Ajaydsouza Contextual Related Posts
SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
ajaydsouza CWE-89
7.5
2014-06-02 CVE-2013-2710 Cross-Site Request Forgery (CSRF) vulnerability in Ajaydsouza Contextual Related Posts
Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via unspecified vectors.
6.8