A number of vulnerabilities have been discovered in the WP Comment Remix 1.4.3 plugin. The following is a short overview of the vulnerabilities discovered: SQL Injection: caused by unsanitized variable “p” in the ajax_comments.php file. Cross Site Scripting: This affects authenticated and unauthenticated users. Cross Site Request Forgery: the form generated through wpcr_do_options_page lacks the WordPress wp_nonce security function. These [...]