The easy-property-listings plugin before 3.4 for WordPress has XSS.
CWE-79
CVE-2019-15827
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
CVE-2019-15829
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
CVE-2019-1583
Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required for the payload to execute on the victim.
CVE-2019-15830
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
CVE-2019-15833
The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
