Vulnerabilities > Wordpress > PAY With Tweet

DATE CVE VULNERABILITY TITLE RISK
2012-10-09 CVE-2012-5350 SQL Injection vulnerability in Wordpress Pay-With-Tweet
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.
network
wordpress CWE-89
6.0
2012-10-09 CVE-2012-5349 Cross-Site Scripting vulnerability in Wordpress Pay-With-Tweet
Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.
network
high complexity
wordpress CWE-79
2.6