Extension WordPress
Vulnérabilités Canto
Cette page rassemble les failles publiées pour Canto, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Canto
9 fiches
Canto <= 3.1.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification
The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOptions() function, which is exposed via…
*-3.1.1
3.1.2
16/04/2026
Canto <= 3.1.1 – Missing Authorization to Unauthenticated File Upload
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file being directly accessible without any authentication, authorization, or nonce checks,…
*-3.1.1
3.1.2
20/03/2026
Canto <= 3.0.8 – Unauthenticated Remote File Inclusion
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting…
*-3.0.8
3.0.9
13/06/2024
Canto <= 3.0.6 – Remote File Inclusion to Code Execution
The Canto plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.6 via the 'abspath' parameter. This is due to the use of the include_once statement on the parameter allowing remote…
*-3.0.6
3.0.7
12/02/2024
Canto <= 3.0.4 – Unauthenticated Remote File Inclusion
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that…
*-3.0.4
3.0.5
09/08/2023
Canto <= 1.9.0 – Blind Server-Side Request Forgery via detail.php
The Canto plugin 1.9.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.
*-1.9.0
2.0.1
04/12/2020
Canto <= 1.9.0 – Blind Server-Side Request Forgery via download.php
The Canto plugin 2.1.1 for WordPress allows includes/lib/download.php?subdomain= SSRF.
*-1.9.0
2.0.1
30/11/2020
Canto <= 1.9.0 – Blind Server-Side Request Forgery via tree.php
The Canto plugin 1.9.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker to make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF.
[*, 2.0.1)
2.0.1
12/03/2020
Canto <= 1.9.0 – Blind Server-Side Request Forgery via get.php
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF.
*-1.9.0
2.0.1
12/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.