Base locale WP Commander

Vulnérabilités WordPress connues

Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.

37 748 vulnérabilités indexées · 44 218 plages de versions · mise à jour le 22/07/2026 à 02:19

41 069 résultats

Page 3 sur 3423

CVE-2026-15160 Moyenne · 4,3
Ninja Forms – Excel Export

Ninja Forms – Excel Export <= 3.3.6 – Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal

The Ninja Forms – Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-3.3.6

Correctif

3.3.7

Publication

16/07/2026

CVE-2026-15159 Moyenne · 4,3
Ninja Forms – Excel Export

Ninja Forms – Excel Export <= 3.3.6 – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter

The Ninja Forms – Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This…

Versions affectées

*-3.3.6

Correctif

3.3.7

Publication

16/07/2026

CVE-2026-11324 Moyenne · 6,1
WooCommerce Placetopay Gateway Honduras

WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.2.2

Correctif

Non indiqué

Publication

16/07/2026

CVE-2026-11324 Moyenne · 6,1
WooCommerce Placetopay Gateway

WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.2.2

Correctif

Non indiqué

Publication

16/07/2026

CVE-2026-11324 Moyenne · 6,1
WooCommerce Placetopay Gateway Uruguay

WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.2.2

Correctif

Non indiqué

Publication

16/07/2026

CVE-2026-11324 Moyenne · 6,1
WooCommerce Placetopay Gateway Colombia

WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.2.2

Correctif

Non indiqué

Publication

16/07/2026

CVE-2026-11324 Moyenne · 6,1
WooCommerce Placetopay Gateway Ecuador

WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.2.2

Correctif

Non indiqué

Publication

16/07/2026

CVE-2026-11324 Moyenne · 6,1
WooCommerce Placetopay Gateway Belice

WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.2.2

Correctif

Non indiqué

Publication

16/07/2026

CVE-2026-2594 Moyenne · 6,4
Smart Custom Fields

Smart Custom Fields <= 5.0.7 – Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it…

Versions affectées

*-5.0.7

Correctif

5.0.8

Publication

16/07/2026

CVE-2026-14782 Moyenne · 4,9
Booking for Appointments and Events Calendar – Amelia

Booking for Appointments and Events Calendar – Amelia <= 2.4.3 – Authenticated (Custom+) SQL Injection via Customer Import

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-2.4.3

Correctif

2.4.4

Publication

16/07/2026

CVE-2026-61943 Moyenne · 5,3
Premium Packages – Sell Digital Products Securely

Premium Packages – Sell Digital Products Securely <= 6.2.0 – Missing Authorization

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.2.0. This makes it possible for unauthenticated…

Versions affectées

*-6.2.0

Correctif

7.0.0

Publication

16/07/2026

Les résultats proviennent de la base de vulnérabilités synchronisée sur ce site. Une absence de résultat ne garantit pas qu’un composant est exempt de faille.