Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
42 817 résultats
Page 2 sur 3569
Affiliate Super Assistent <= 1.10.2 – Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.10.2
1.10.3
31/08/2026
Photo Gallery by Ays <= 6.8.2 – Authenticated (Administrator+) SQL Injection via 's' Parameter
The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient escaping on the user supplied…
*-6.8.2
6.8.3
31/08/2026
Persistent Login <= 3.1.0 – Authenticated (Subscriber+) SQL Injection via 'wppl_device_id' Cookie
The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-3.1.0
3.1.1
31/08/2026
Master Addons for Elementor <= 3.1.9 – Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the…
*-3.1.9
3.2.0
31/08/2026
Live Composer <= 2.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes…
*-2.1.19
2.1.20
31/08/2026
Live Composer <= 2.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modules_area shortcodes in versions up to, and including, 2.1.19. This is due…
*-2.1.19
2.1.20
31/08/2026
Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 – Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and including, 5.8.1 due to insufficient input sanitization and output escaping. This…
*-5.8.1
5.9.0
31/08/2026
LearnPress <= 4.4.4 – Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient escaping on the user supplied parameter and…
*-4.4.4
4.4.5
31/08/2026
Frontend Admin by DynamiApps <= 3.29.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.29.11
3.29.12
31/08/2026
Frontend Admin by DynamiApps <= 3.29.12 – Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated…
*-3.29.12
3.29.13
31/08/2026
WPLP Cookie Consent <= 4.4.1 – Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with…
*-4.4.1
4.4.2
31/08/2026
MyHome Core <= 4.4.5 – Authentication Bypass to Account Takeover via Activation Token
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function.…
*-4.4.5
4.4.6
29/08/2026