Extension WordPress
Vulnérabilités Awesome Support – WordPress HelpDesk & Support Plugin, page 2
Cette page rassemble les failles publiées pour Awesome Support – WordPress HelpDesk & Support Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Awesome Support – WordPress HelpDesk & Support Plugin
27 fiches
Awesome Support <= 6.1.1 – Insecure Direct Object Reference to (Subscriber+) Ticket Export
The Awesome Support plugin for WordPress is vulnerable to Insecure Direct Object Reference to (Subscriber+) Ticket Export in versions up to, and including, 6.1.1. Improper protection of the 'file' parameter used to control the user id value during…
*-6.1.1
6.1.2
07/11/2022
Awesome Support <= 6.0.7 – Authenticated Stored Cross-Site Scripting
The Awesome Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web…
*-6.0.7
6.0.8
14/09/2022
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.0.6 – Reflected Cross-Site Scripting
The "Awesome Support – WordPress HelpDesk & Support Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 6.0.6 due to insufficient input sanitization and output escaping. This makes…
*-6.0.6
6.0.7
26/11/2021
Titan Framework <= (Various Versions) – Reflected Cross-Site Scripting
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues.
*-6.0.10
6.0.11
09/08/2021
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.0.13 – Cross-Site Scripting via post_title
The awesome-support plugin 6.0.13 and below for WordPress allows XSS via the post_title parameter.
*-6.0.13
6.0.14
06/01/2020
Awesome Support – WordPress HelpDesk & Support Plugin <= 3.1.6 – Arbitrary Shortcode Execution
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
[*, 3.1.7)
3.1.7
15/05/2015
Awesome Support – WordPress HelpDesk & Support Plugin < 3.1.7 – Cross-Site Scripting
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
[*, 3.1.7)
3.1.7
15/05/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.