Vulnerabilities > Mg12

DATE CVE VULNERABILITY TITLE RISK
2012-02-14 CVE-2012-1068 Cross-Site Scripting vulnerability in Mg12 Wp-Recentcomments
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
4.3
2012-02-14 CVE-2012-1067 SQL Injection vulnerability in Mg12 Wp-Recentcomments 2.0.7
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php.
network
low complexity
mg12 wordpress CWE-89
7.5