Extension WordPress
Vulnérabilités Group Chat & Video Chat by AtomChat
Cette page rassemble les failles publiées pour Group Chat & Video Chat by AtomChat, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Group Chat & Video Chat by AtomChat
5 fiches
Group Chat & Video Chat by AtomChat <= 1.1.7 – Missing Authorization to Authenticated (Subscriber+) Plugin Options Update
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'atomchat_update_auth_ajax' and 'atomchat_update_layout_ajax' functions in all versions up to, and including, 1.1.7…
*-1.1.7
1.1.8
20/03/2026
AtomChat <= 1.1.7 – Missing Authorization
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.7. This makes it possible for…
*-1.1.7
1.1.8
01/04/2025
AtomChat <= 1.1.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.1.6
Non indiqué
31/03/2025
AtomChat <= 1.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via atomchat Shortcode
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping…
*-1.1.5
1.1.6
31/10/2024
AtomChat <= 1.1.4 – Missing Authorization via credits REST API Endpoint
The AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'credits' REST API function in versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers…
*-1.1.4
1.1.5
24/10/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.