Extension WordPress
Vulnérabilités Car Dealer (Dealership) and Vehicle sales
Cette page rassemble les failles publiées pour Car Dealer (Dealership) and Vehicle sales, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Car Dealer (Dealership) and Vehicle sales
3 fiches
Car Dealer <= 4.46 – Missing Authorization
The Car Dealer plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check on the cardealer_dbase_get_callback function in versions up to, and including, 4.46. This makes it possible for authenticated attackers, with…
*-4.46
4.48
11/12/2024
Car Dealer <= 4.15 – Authenticated (Admin+) Content Injection
The Car Dealer (Dealership) and Vehicle sales plugin for WordPress is vulnerable to unauthorized content injection due to insufficient input validation in all versions up to, and including, 4.15. This makes it possible for authenticated attackers, with administrator-level…
*-4.15
4.16
25/04/2024
Car Dealer <= 3.04 – Missing Authorization to Arbitrary Plugin Installation
The Car Dealer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cardealer_install_plugin() function in versions up to, and including, 3.04. This makes it possible for authenticated attackers with minimal permission,…
*-3.04
3.05
18/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.