Extension WordPress

Vulnérabilités Categorify – WordPress Media Library Category & File Manager

Cette page rassemble les failles publiées pour Categorify – WordPress Media Library Category & File Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
11Avec correctif
6,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Categorify – WordPress Media Library Category & File Manager

12 fiches

CVE-2024-1650 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Missing Authorization in categorifyAjaxRenameCategory

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1649 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Missing Authorization in categorifyAjaxDeleteCategory

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1910 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Cross-Site Request Forgery via categorifyAjaxClearCategory

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxClearCategory function. This makes it possible for unauthenticated…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1652 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Missing Authorization in categorifyAjaxClearCategory

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1906 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Cross-Site Request Forgery via categorifyAjaxAddCategory

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxAddCategory function. This makes it possible for unauthenticated…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1912 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Cross-Site Request Forgery via categorifyAjaxUpdateFolderPosition

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1909 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Cross-Site Request Forgery via categorifyAjaxRenameCategory

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxRenameCategory function. This makes it possible for unauthenticated…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1653 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Missing Authorization in categorifyAjaxUpdateFolderPosition

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-1907 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Cross-Site Request Forgery via categorifyAjaxDeleteCategory

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxDeleteCategory function. This makes it possible for unauthenticated…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2024-0385 Moyenne · 4,3
Categorify – WordPress Media Library Category & File Manager

Categorify <= 1.0.7.4 – Missing Authorization in categorifyAjaxAddCategory

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxAddCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.0.7.4

Correctif

1.0.7.5

Publication

26/02/2024

CVE-2022-4974 Moyenne · 6,3
Categorify – WordPress Media Library Category & File Manager

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 1.0.5)

Correctif

1.0.5

Publication

04/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités