The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
CWE-79
CVE-2019-15837
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15838
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
CVE-2019-15750
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2019-15777
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
CVE-2019-15778
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
