Extension WordPress

Vulnérabilités Branda – White Label & Branding, Free Login Page Customizer

Cette page rassemble les failles publiées pour Branda – White Label & Branding, Free Login Page Customizer, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
2Critiques
8Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Branda – White Label & Branding, Free Login Page Customizer

8 fiches

CVE-2026-11551 Critique · 9,8
Branda – White Label & Branding, Free Login Page Customizer

Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 – Unauthenticated Privilege Escalation via Account Takeover

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password.…

Versions affectées

*-3.4.29

Correctif

3.4.31

Publication

19/06/2026

CVE-2025-14998 Critique · 9,8
Branda – White Label & Branding, Free Login Page Customizer

Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 – Unauthenticated Privilege Escalation via Account Takeover

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password.…

Versions affectées

*-3.4.24

Correctif

3.4.29

Publication

01/01/2026

CVE-2024-9371 Moyenne · 6,1
Branda – White Label & Branding, Free Login Page Customizer

Branda – White Label & Branding, Custom Login Page Customizer <= 3.4.19 – Reflected Cross-Site Scripting

The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and…

Versions affectées

*-3.4.21

Correctif

3.4.22

Publication

20/11/2024

CVE-2024-6554 Moyenne · 5,3
Branda – White Label & Branding, Free Login Page Customizer

Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 – Unauthenticated Full Path Disclosure

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access…

Versions affectées

*-3.4.18

Correctif

3.4.19

Publication

10/07/2024

CVE-2024-37239 Moyenne · 4,4
Branda – White Label & Branding, Free Login Page Customizer

Branda <= 3.4.17 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…

Versions affectées

*-3.4.17

Correctif

3.4.18

Publication

28/06/2024

CVE-2024-5191 Moyenne · 6,4
Branda – White Label & Branding, Free Login Page Customizer

Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.17 – Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload

The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output…

Versions affectées

*-3.4.17

Correctif

3.4.18

Publication

20/06/2024

Vulnérabilité Moyenne · 4,4
Branda – White Label & Branding, Free Login Page Customizer

Branda – White Label WordPress <= 3.4.8.1 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

Versions affectées

*-3.4.8.1

Correctif

3.4.9

Publication

16/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités