Extension WordPress

Vulnérabilités Advanced Form Integration , Connect Forms to 200+ Apps

Cette page rassemble les failles publiées pour Advanced Form Integration , Connect Forms to 200+ Apps, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
6,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Advanced Form Integration , Connect Forms to 200+ Apps

11 fiches

CVE-2026-42659 Moyenne · 4,3
Advanced Form Integration , Connect Forms to 200+ Apps

AFI – The Easiest Integration Plugin <= 1.126.12 – Missing Authorization

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.126.12. This makes it possible for authenticated attackers,…

Versions affectées

*-1.126.12

Correctif

1.127.0

Publication

29/04/2026

CVE-2024-13123 Moyenne · 4,4
Advanced Form Integration , Connect Forms to 200+ Apps

AFI – The Easiest Integration Plugin <= 1.99.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.99.0

Correctif

1.100.0

Publication

03/03/2025

CVE-2024-13122 Moyenne · 4,4
Advanced Form Integration , Connect Forms to 200+ Apps

AFI – The Easiest Integration Plugin <= 1.99.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.99.0

Correctif

1.100.0

Publication

03/03/2025

CVE-2024-56293 Moyenne · 4,4
Advanced Form Integration , Connect Forms to 200+ Apps

Advanced Form Integration <= 1.95.0 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.95.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…

Versions affectées

*-1.95.0

Correctif

1.97.0

Publication

03/01/2025

CVE-2024-10877 Moyenne · 6,1
Advanced Form Integration , Connect Forms to 200+ Apps

AFI – The Easiest Integration Plugin <= 1.92.0 – Reflected Cross-Site Scripting

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0.…

Versions affectées

*-1.92.0

Correctif

1.92.1

Publication

12/11/2024

CVE-2024-43340 Moyenne · 4,3
Advanced Form Integration , Connect Forms to 200+ Apps

AFI – The Easiest Integration Plugin <= 1.89.4 – Cross-Site Request Forgery

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.89.4. This is due to missing or incorrect nonce validation on the adfoin_duplicate_integration() function. This makes…

Versions affectées

*-1.89.4

Correctif

1.89.6

Publication

16/08/2024

CVE-2024-2387 Moyenne · 6,1
Advanced Form Integration , Connect Forms to 200+ Apps

Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 – SQL Injection to Reflected Cross-Site Scripting via integration_id

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due…

Versions affectées

*-1.82.0

Correctif

1.82.6

Publication

19/03/2024

CVE-2023-50853 Moyenne · 6,6
Advanced Form Integration , Connect Forms to 200+ Apps

Advanced Form Integration <= 1.75.0 – Authenticated(Administrator+) SQL Injection

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.76.0 (exclusive) due to…

Versions affectées

[*, 1.76.0)

Correctif

1.76.0

Publication

21/12/2023

CVE-2023-33999 Moyenne · 6,1
Advanced Form Integration , Connect Forms to 200+ Apps

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-1.69.0

Correctif

1.69.1

Publication

18/07/2023

CVE-2022-47173 Moyenne · 4,4
Advanced Form Integration , Connect Forms to 200+ Apps

Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 – Authenticated (Admin+) Cross Site Scripting

The Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.62.0 due to insufficient…

Versions affectées

*-1.62.0

Correctif

1.63.0

Publication

27/01/2023

CVE-2022-4974 Moyenne · 6,3
Advanced Form Integration , Connect Forms to 200+ Apps

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 1.49.0)

Correctif

1.49.0

Publication

04/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités