Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
41 069 résultats
Page 3 sur 3423
Ninja Forms – Excel Export <= 3.3.6 – Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal
The Ninja Forms – Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-3.3.6
3.3.7
16/07/2026
Ninja Forms – Excel Export <= 3.3.6 – Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter
The Ninja Forms – Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This…
*-3.3.6
3.3.7
16/07/2026
WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.2.2
Non indiqué
16/07/2026
WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.2.2
Non indiqué
16/07/2026
WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.2.2
Non indiqué
16/07/2026
WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.2.2
Non indiqué
16/07/2026
WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.2.2
Non indiqué
16/07/2026
WooCommerce Placetopay Gateway <= 3.2.2 – Reflected Cross-Site Scripting via 'redirect-url'
The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.2.2
Non indiqué
16/07/2026
Smart Custom Fields <= 5.0.7 – Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title
The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it…
*-5.0.7
5.0.8
16/07/2026
Bricksforge <= 3.1.8.6 – Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field…
*-3.1.8.6
3.1.8.7
16/07/2026
Booking for Appointments and Events Calendar – Amelia <= 2.4.3 – Authenticated (Custom+) SQL Injection via Customer Import
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter…
*-2.4.3
2.4.4
16/07/2026
Premium Packages – Sell Digital Products Securely <= 6.2.0 – Missing Authorization
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.2.0. This makes it possible for unauthenticated…
*-6.2.0
7.0.0
16/07/2026