Base locale WP Commander

Vulnérabilités WordPress connues

Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.

39 474 vulnérabilités indexées · 46 175 plages de versions · mise à jour le 31/08/2026 à 19:29

42 813 résultats

Page 3 sur 3568

CVE-2026-76581 Critique · 9,8
WPMU DEV Dashboard

WPMU DEV Dashboard <= 5.0.1 – Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions,…

Versions affectées

*-5.0.1

Correctif

5.0.2

Publication

27/08/2026

CVE-2026-16654 Moyenne · 6,4
Avada (Fusion) Builder

Avada (Fusion) Builder <= 3.15.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attribute in all versions up to, and including, 3.15.6 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.15.6

Correctif

3.16

Publication

27/08/2026

CVE-2026-16759 Moyenne · 6,5
Tutor LMS – eLearning and online course solution

Tutor LMS <= 4.0.5 – Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is…

Versions affectées

*-4.0.5

Correctif

4.0.6

Publication

27/08/2026

CVE-2026-18983 Élevée · 7,5
One User Avatar | User Profile Picture

One User Avatar | User Profile Picture <= 2.5.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter

The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in…

Versions affectées

*-2.5.4

Correctif

2.5.5

Publication

27/08/2026

CVE-2026-18324 Élevée · 7,2
Forminator Forms – Contact Form, Payment Form & Custom Form Builder

Forminator Forms <= 1.57.0.1 – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization…

Versions affectées

*-1.57.0.1

Correctif

1.57.0.2

Publication

27/08/2026

CVE-2026-76053 Élevée · 7,2
TranslatePress – Translate Multilingual sites with AI Translation

TranslatePress <= 3.3.3 – Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization…

Versions affectées

*-3.3.3

Correctif

3.3.4

Publication

27/08/2026

CVE-2026-77365 Élevée · 7,2
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization

Optimole <= 4.2.10 – Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and…

Versions affectées

*-4.2.10

Correctif

4.2.11

Publication

27/08/2026

CVE-2026-15798 Moyenne · 6,4
Smart Slider 3

Smart Slider 3 <= 3.5.1.38 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.5.1.38

Correctif

3.5.1.39

Publication

27/08/2026

CVE-2026-6176 Élevée · 7,2
Customer Reviews for WooCommerce

Customer Reviews for WooCommerce <= 5.106.0 – Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on…

Versions affectées

*-5.106.0

Correctif

5.107.0

Publication

27/08/2026

CVE-2026-5096 Moyenne · 5,3
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.4.4 – Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

27/08/2026

Les résultats proviennent de la base de vulnérabilités synchronisée sur ce site. Une absence de résultat ne garantit pas qu’un composant est exempt de faille.