Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
41 069 résultats
Page 2 sur 3423
WordPress Core 6.8 – 7.0.1 – Unauthenticated SQL Injection via author__not_in Parameter
WordPress Core is vulnerable to generic SQL Injection via the 'author__not_in' parameter in versions 6.8 – 7.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
[6.8, 6.8.5), [6.9, 6.9.5), [7.0, 7.0.2)
6.8.6, 6.9.5, 7.0.2
17/07/2026
HubSpot All-In-One Marketing <= 11.3.62 – Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script
The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for…
*-11.3.62
11.3.64
16/07/2026
WP Hotel Booking <= 2.3.2 – Reflected Cross-Site Scripting via 'check_in_date' Parameter
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.3.2
2.3.3
16/07/2026
pCloud WP Backup <= 2.0.3 – Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract…
*-2.0.3
2.0.4
16/07/2026
ChatHelp <= 3.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1…
*-3.5.1
3.5.2
16/07/2026
LearnPress <= 4.4.1 – Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated…
*-4.4.1
4.4.2
16/07/2026
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a…
*-1.17.6
1.17.7
16/07/2026
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 – Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function.…
*-4.16.18
4.16.19
16/07/2026
Ninja Forms – Excel Export <= 3.3.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter
The Ninja Forms – Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress…
*-3.3.6
3.3.7
16/07/2026
Kirki <= 6.0.13 – Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with…
*-6.0.13
6.0.14
16/07/2026
Fense Proxy & VPN Blocker <= 3.0.1 – Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The…
*-3.0.1
3.0.2
16/07/2026
Kali Forms <= 2.4.18 – Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
The Kali Forms , Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping.…
*-2.4.18
2.4.19
16/07/2026