Extension WordPress
Vulnérabilités Astra Pro Addon
Cette page rassemble les failles publiées pour Astra Pro Addon, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Astra Pro Addon
2 fiches
Astra Pro <= 4.3.1 – Authenticated(Contributor+) Remote Code Execution via Metabox
The Astra Pro Addon plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.3.1 via the ast-advanced-hook-php-code meta field. This makes it possible for authenticated attackers, with contributor access and above,…
*-4.3.1
4.3.2
05/12/2023
Astra Pro Addon <= 3.5.1 – Unauthenticated SQL Injection
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL…
[*, 3.5.2)
3.5.2
08/07/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.