Extension WordPress
Vulnérabilités Blackhole for Bad Bots
Cette page rassemble les failles publiées pour Blackhole for Bad Bots, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Blackhole for Bad Bots
2 fiches
Blackhole for Bad Bots <= 3.8 – Unauthenticated Stored Cross-Site Scripting via User-Agent HTTP Header
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The…
*-3.8
3.8.1
25/03/2026
Blackhole for Bad Bots <= 3.3.1 – Arbitrary IP Address Blocking via IP Spoofing
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking…
[*, 3.3.2)
3.3.2
31/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.