Extension WordPress
Vulnérabilités Buy Me a Coffee – Button and Widget Plugin
Cette page rassemble les failles publiées pour Buy Me a Coffee – Button and Widget Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Buy Me a Coffee – Button and Widget Plugin
4 fiches
Buy Me a Coffee – Button and Widget Plugin <= 3.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.6 due to insufficient sanitization and escaping on the 'text value set via the…
*-3.6
3.7
13/07/2023
Buy Me a Coffee – Button and Widget Plugin <= 3.7 – Missing Authorization
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and…
*-3.7
3.8
10/07/2023
Buy Me a Coffee – Button and Widget Plugin <= 3.7 – Cross-Site Request Forgery
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including,…
*-3.7
3.8
10/07/2023
Buy Me a Coffee – Button and Widget Plugin <= 3.6 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Buy Me a Coffee – Button and Widget Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.6 due to insufficient input sanitization and output escaping. This…
*-3.6
3.7
19/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.