Extension WordPress
Vulnérabilités AnyComment
Cette page rassemble les failles publiées pour AnyComment, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AnyComment
8 fiches
AnyComment <= 0.3.6 – Missing Authorization
The AnyComment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 0.3.6. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-0.3.6
Non indiqué
31/12/2025
AnyComment <= 0.3.6 – Authenticated (Subscriber+) SQL Injection
The AnyComment plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-0.3.6
Non indiqué
08/10/2025
AnyComment <= 0.3.6 – Unauthenticated Local File Inclusion
The AnyComment plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.3.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
*-0.3.6
Non indiqué
12/07/2025
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-0.0.98
0.0.99
18/07/2023
AnyComment <= 0.2.17 – Cross-Site Request Forgery
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack
[*, 0.2.18)
0.2.18
19/01/2022
AnyComment <= 0.2.17 – Race Condition
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users
[*, 0.2.18)
0.2.18
19/01/2022
AnyComment <= 0.3.4 – Open Redirect via redirect parameter
The AnyComment plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 0.3.4. This is due to an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being…
[*, 0.3.5)
0.3.5
20/12/2021
AnyComment <= 0.0.32 – Cross-Site Scripting
The AnyComment plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.0.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that…
*-0.0.32
0.0.33
17/07/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.