Base locale WP Commander

Vulnérabilités WordPress connues

Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.

39 478 vulnérabilités indexées · 46 179 plages de versions · mise à jour le 31/08/2026 à 19:29

42 817 résultats

Page 2 sur 3569

CVE-2026-19573 Élevée · 7,2
Affiliate Super Assistent

Affiliate Super Assistent <= 1.10.2 – Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function

The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.10.2

Correctif

1.10.3

Publication

31/08/2026

CVE-2026-76006 Moyenne · 4,9
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays <= 6.8.2 – Authenticated (Administrator+) SQL Injection via 's' Parameter

The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient escaping on the user supplied…

Versions affectées

*-6.8.2

Correctif

6.8.3

Publication

31/08/2026

CVE-2026-75921 Élevée · 7,2
Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits

Master Addons for Elementor <= 3.1.9 – Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the…

Versions affectées

*-3.1.9

Correctif

3.2.0

Publication

31/08/2026

CVE-2026-16787 Moyenne · 6,4
Live Composer – Free WordPress Website Builder

Live Composer <= 2.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.1.19

Correctif

2.1.20

Publication

31/08/2026

CVE-2026-13203 Moyenne · 6,4
Live Composer – Free WordPress Website Builder

Live Composer <= 2.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modules_area shortcodes in versions up to, and including, 2.1.19. This is due…

Versions affectées

*-2.1.19

Correctif

2.1.20

Publication

31/08/2026

CVE-2026-19796 Élevée · 7,2
Listdom: AI-powered Business Directory with Classifieds Ads Listings

Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 – Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and including, 5.8.1 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-5.8.1

Correctif

5.9.0

Publication

31/08/2026

CVE-2026-77823 Moyenne · 4,9
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress <= 4.4.4 – Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-4.4.4

Correctif

4.4.5

Publication

31/08/2026

CVE-2026-12747 Moyenne · 6,4
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.29.11

Correctif

3.29.12

Publication

31/08/2026

CVE-2026-19952 Élevée · 7,5
Frontend Admin by DynamiApps

Frontend Admin by DynamiApps <= 3.29.12 – Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated…

Versions affectées

*-3.29.12

Correctif

3.29.13

Publication

31/08/2026

CVE-2026-75865 Critique · 9,8
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

WPLP Cookie Consent <= 4.4.1 – Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with…

Versions affectées

*-4.4.1

Correctif

4.4.2

Publication

31/08/2026

Les résultats proviennent de la base de vulnérabilités synchronisée sur ce site. Une absence de résultat ne garantit pas qu’un composant est exempt de faille.