Extension WordPress
Vulnérabilités Advanced Form Integration , Connect Forms to 200+ Apps
Cette page rassemble les failles publiées pour Advanced Form Integration , Connect Forms to 200+ Apps, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Advanced Form Integration , Connect Forms to 200+ Apps
11 fiches
AFI – The Easiest Integration Plugin <= 1.126.12 – Missing Authorization
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.126.12. This makes it possible for authenticated attackers,…
*-1.126.12
1.127.0
29/04/2026
AFI – The Easiest Integration Plugin <= 1.99.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it…
*-1.99.0
1.100.0
03/03/2025
AFI – The Easiest Integration Plugin <= 1.99.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it…
*-1.99.0
1.100.0
03/03/2025
Advanced Form Integration <= 1.95.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.95.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access…
*-1.95.0
1.97.0
03/01/2025
AFI – The Easiest Integration Plugin <= 1.92.0 – Reflected Cross-Site Scripting
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0.…
*-1.92.0
1.92.1
12/11/2024
AFI – The Easiest Integration Plugin <= 1.89.4 – Cross-Site Request Forgery
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.89.4. This is due to missing or incorrect nonce validation on the adfoin_duplicate_integration() function. This makes…
*-1.89.4
1.89.6
16/08/2024
Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 – SQL Injection to Reflected Cross-Site Scripting via integration_id
The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due…
*-1.82.0
1.82.6
19/03/2024
Advanced Form Integration <= 1.75.0 – Authenticated(Administrator+) SQL Injection
The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.76.0 (exclusive) due to…
[*, 1.76.0)
1.76.0
21/12/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.69.0
1.69.1
18/07/2023
Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 – Authenticated (Admin+) Cross Site Scripting
The Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.62.0 due to insufficient…
*-1.62.0
1.63.0
27/01/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.49.0)
1.49.0
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.