Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
42 794 résultats
Page 1 sur 3567
MyHome Core <= 4.4.5 – Authentication Bypass to Account Takeover via Activation Token
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function.…
*-4.4.5
4.4.6
29/08/2026
Custom User Registration Fields for WooCommerce <= 2.2.3 – Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store…
*-2.2.3
2.2.4
29/08/2026
SAML Single Sign On <= 5.4.6 – Unauthenticated Authentication Bypass via X.509 Certificate Poisoning
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an…
*-5.4.6
5.4.7
29/08/2026
Sigma Forms Pro <= 1.4.5 – Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all…
*-1.4.5
1.4.6
28/08/2026
GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 – Unauthenticated PHP Object Injection to Remote Code Execution
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.16.7.1 via unsafe handling of serialized donor account data during the legacy donation process.…
*-4.16.7.1
4.16.7.2
28/08/2026
WPMU DEV Dashboard <= 5.0.1 – Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions,…
*-5.0.1
5.0.2
27/08/2026
Avada (Fusion) Builder <= 3.15.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attribute in all versions up to, and including, 3.15.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.15.6
3.16
27/08/2026
Tutor LMS <= 4.0.5 – Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is…
*-4.0.5
4.0.6
27/08/2026
One User Avatar | User Profile Picture <= 2.5.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in…
*-2.5.4
2.5.5
27/08/2026
LiteSpeed Cache <= 7.8.1 – Unauthenticated Stored Cross-Site Scripting via Comment Content
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-7.8.1
7.9
27/08/2026
LiteSpeed Cache <= 7.7 – Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted « tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip…
*-7.7
7.8
27/08/2026
Forminator Forms <= 1.57.0.1 – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization…
*-1.57.0.1
1.57.0.2
27/08/2026