Multiple vulnerabilities in WordPress plugin “WordPress Landing Pages”
The first vulnerability is an authenticated SQL injection vulnerability in the WordPress Landing Pages plugin. This vulnerability is caused due to the lack of proper sanitization of user-supplied input in the 'post' parameter of the 'modules/module.ab-testing.php' script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script. The second vulnerability is an authenticated cross-site scripting vulnerability in the WordPress Landing Pages plugin. This vulnerability is caused due to the lack of proper sanitization of user-supplied input in the 'sc' parameter of the 'shared/shortcodes/inbound-shortcodes.php' script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script.