Extension WordPress
Vulnérabilités Author Avatars List/Block
Cette page rassemble les failles publiées pour Author Avatars List/Block, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Author Avatars List/Block
4 fiches
Author Avatars List/Block <= 2.1.25 – Missing Authorization
The Author Avatars List/Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.25. This makes it possible for unauthenticated attackers to perform an…
*-2.1.25
Non indiqué
23/02/2026
Author Avatars List/Block <= 2.1.23 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Author Avatars List/Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-2.1.23
2.1.24
07/01/2025
Author Avatars List/Block <= 2.1.21 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Author Avatars List/Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access…
*-2.1.21
2.1.22
30/09/2024
Author Avatars List/Block <= 2.1.17 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Author Avatars List/Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 2.1.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.1.17
2.1.18
06/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.