Extension WordPress

Vulnérabilités Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan

Cette page rassemble les failles publiées pour Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
4Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan

4 fiches

CVE-2024-1861 Moyenne · 4,3
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan

Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.52 – Missing Authorization to Authenticated (Subscriber+) Table Truncation

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_truncate_scan_table() function in all versions up…

Versions affectées

*-4.52

Correctif

4.53

Publication

27/02/2024

CVE-2024-1860 Moyenne · 6,5
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan

Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan <= 4.51 – Missing Authorization to Unauthenticated IP Address Whitelist

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the antihacker_add_whitelist() function in all versions up…

Versions affectées

*-4.51

Correctif

4.52

Publication

27/02/2024

CVE-2023-50858 Moyenne · 4,3
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan

Anti Hacker <= 4.34 – Cross-Site Request Forgery via antihacker_ajax_scan

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 4.35 (exclusive). This is due to missing or incorrect nonce…

Versions affectées

[*, 4.35)

Correctif

4.35

Publication

22/12/2023

CVE-2022-3880 Moyenne · 6,5
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan

Anti Hacker <= 4.19 – Missing Authorization to Arbitrary Plugin Install

The Anti Hacker plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the antihacker_install_plugin() function in versions up to, and including, 4.19. This makes it possible for authenticated attackers with minimal permission,…

Versions affectées

*-4.19

Correctif

4.20

Publication

21/11/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités