Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
41 069 résultats
Page 1 sur 3423
Contact Form 7 – Dynamic Text Extension <= 5.0.6 – Unauthenticated Arbitrary Shortcode Execution
The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action…
*-5.0.3
Non indiqué
22/07/2026
Ultimate Addons for Elementor <= 2.9.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes…
*-2.9.1
2.9.2
21/07/2026
WP Foodbakery <= 4.9 – Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with…
*-4.9
Non indiqué
21/07/2026
Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and…
*-6.6.11
6.7.0
20/07/2026
Tutor LMS Elementor Addons <= 4.0.0 – Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation
The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers.…
*-4.0.0
Non indiqué
20/07/2026
MapSVG <= 8.14.0 – Authenticated (Administrator+) Arbitrary File Upload via '/mapsvg/v1/svgfile' Endpoint
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that…
*-8.14.0
8.14.1
20/07/2026
Easy Form Builder by WhiteStudio <= 4.0.11 – Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid')…
*-4.0.11
4.0.12
20/07/2026
WPForms <= 2.0.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions…
*-2.0.0.1
2.0.0.2
20/07/2026
Essential Addons for Elementor <= 6.6.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input…
*-6.6.11
6.7.0
20/07/2026
Spectra Gutenberg Blocks <= 2.19.28 – Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and…
*-2.19.28
2.19.29
20/07/2026
W3SC Elementor to Zoho CRM <= 2.2.0 – Cross-Site Request Forgery to Settings Update
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes…
*-2.2.0
Non indiqué
17/07/2026
WordPress Core 6.9 – 7.0.1 – Remote Code Execution via REST API Batch Request Route Confusion
WordPress Core is vulnerable to Remote Code Execution in all versions 6.9 to 7.0.1 via the REST API batch request endpoint (/wp-json/batch/v1). This is due to a route/validation desynchronization that allows a validated sub-request to be dispatched to…
[6.9, 6.9.5), [7.0, 7.0.2)
6.9.5, 7.0.2
17/07/2026