The PrettyLinks plugin for WordPress has a SQL Injection vulnerability via the 's' parameter on the Pretty Links listing page in versions up to 3.6.20. Authenticated attackers with Administrator-level access can append SQL queries to extract sensitive database information. This vulnerability has a CVSS score of 4.9 and is considered Medium severity. The vulnerability is caused by insufficient escaping on [truncated]
The Members – Membership & User Role Editor Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of access-restricted posts, and use per-page pagination as a boolean oracle to infer keywords and [truncated]