Extension WordPress
Vulnérabilités Banner Management For WooCommerce
Cette page rassemble les failles publiées pour Banner Management For WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Banner Management For WooCommerce
4 fiches
Woocommerce Category Banner Management <= 2.5.1 – Authenticated (Contributor+) PHP Object Injection
The Woocommerce Category Banner Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.5.1
Non indiqué
16/02/2026
Woocommerce Category Banner Management <= 2.4.1 – Cross-Site Request Forgery
The Woocommerce Category Banner Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.1. This is due to missing nonce validation on the wcbm_save_shop_page_banner_data() function. This makes it possible for unauthenticated…
*-2.4.1
2.4.3
26/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.2.3)
2.2.3
04/03/2022
Woocommerce Category Banner Management <= 1.1.0 – Missing Authorization
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.
*-1.1.0
1.1.1
29/05/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.