Base locale WP Commander
Vulnérabilités WordPress connues
Recherchez une extension, un thème, une version de WordPress ou une référence CVE dans la base synchronisée localement.
42 813 résultats
Page 3 sur 3568
WPMU DEV Dashboard <= 5.0.1 – Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions,…
*-5.0.1
5.0.2
27/08/2026
Avada (Fusion) Builder <= 3.15.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attribute in all versions up to, and including, 3.15.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.15.6
3.16
27/08/2026
Tutor LMS <= 4.0.5 – Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all versions up to, and including, 4.0.5 via the tutor_course_filter_ajax AJAX action. This is…
*-4.0.5
4.0.6
27/08/2026
One User Avatar | User Profile Picture <= 2.5.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in…
*-2.5.4
2.5.5
27/08/2026
LiteSpeed Cache <= 7.8.1 – Unauthenticated Stored Cross-Site Scripting via Comment Content
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-7.8.1
7.9
27/08/2026
LiteSpeed Cache <= 7.7 – Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted « tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip…
*-7.7
7.8
27/08/2026
Forminator Forms <= 1.57.0.1 – Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization…
*-1.57.0.1
1.57.0.2
27/08/2026
TranslatePress <= 3.3.3 – Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization…
*-3.3.3
3.3.4
27/08/2026
Optimole <= 4.2.10 – Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and…
*-4.2.10
4.2.11
27/08/2026
Smart Slider 3 <= 3.5.1.38 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.5.1.38
3.5.1.39
27/08/2026
Customer Reviews for WooCommerce <= 5.106.0 – Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on…
*-5.106.0
5.107.0
27/08/2026
Everest Forms <= 3.4.4 – Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload…
*-3.4.4
3.4.5
27/08/2026