Extension WordPress

Vulnérabilités EleForms – All In One Form Integration including DB for Elementor

Cette page rassemble les failles publiées pour EleForms – All In One Form Integration including DB for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
2Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de EleForms – All In One Form Integration including DB for Elementor

5 fiches

CVE-2024-6628 Moyenne · 4,3
EleForms – All In One Form Integration including DB for Elementor

EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.9 – Cross-Site Request Forgery

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.9.9. This is due to missing or incorrect nonce validation…

Versions affectées

*-2.9.9.9

Correctif

Non indiqué

Publication

15/11/2024

CVE-2024-6626 Moyenne · 5,3
EleForms – All In One Form Integration including DB for Elementor

EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.9 – Missing Authorization

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in all versions up to, and including,…

Versions affectées

*-2.9.9.9

Correctif

Non indiqué

Publication

05/11/2024

CVE-2024-2082 Élevée · 7,2
EleForms – All In One Form Integration including DB for Elementor

EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.7 – Unauthenticated Stored Cross-Site Scripting

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 2.9.9.7 due to insufficient input sanitization and…

Versions affectées

*-2.9.9.7

Correctif

2.9.9.8

Publication

16/04/2024

CVE-2024-2043 Moyenne · 5,3
EleForms – All In One Form Integration including DB for Elementor

EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.7 – Missing Authorization to Sensitive Information Exposure

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and…

Versions affectées

*-2.9.9.7

Correctif

2.9.9.8

Publication

16/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités