Extension WordPress
Vulnérabilités Branda – White Label & Branding, Free Login Page Customizer
Cette page rassemble les failles publiées pour Branda – White Label & Branding, Free Login Page Customizer, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Branda – White Label & Branding, Free Login Page Customizer
8 fiches
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 – Unauthenticated Privilege Escalation via Account Takeover
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password.…
*-3.4.29
3.4.31
19/06/2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 – Unauthenticated Privilege Escalation via Account Takeover
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password.…
*-3.4.24
3.4.29
01/01/2026
Branda – White Label & Branding, Custom Login Page Customizer <= 3.4.19 – Reflected Cross-Site Scripting
The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and…
*-3.4.21
3.4.22
20/11/2024
Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 – Unauthenticated Full Path Disclosure
The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.18. This is due the plugin utilizing composer without preventing direct access…
*-3.4.18
3.4.19
10/07/2024
Branda <= 3.4.17 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
*-3.4.17
3.4.18
28/06/2024
Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.17 – Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mime_types’ parameter in all versions up to, and including, 3.4.17 due to insufficient input sanitization and output…
*-3.4.17
3.4.18
20/06/2024
Branda <= 3.4.14 – IP Address Spoofing
The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.4.14 due to insufficient IP address validation and use of user-supplied HTTP…
*-3.4.14
3.4.15
27/12/2023
Branda – White Label WordPress <= 3.4.8.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Branda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-3.4.8.1
3.4.9
16/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.