Extension WordPress

Vulnérabilités Geo Controller

Cette page rassemble les failles publiées pour Geo Controller, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Geo Controller

7 fiches

CVE-2024-7380 Moyenne · 4,3
Geo Controller

Geo Controller <= 8.7.3 – Missing Authorization to Authenticated (Subscriber+) Menu Creation/Deletion

The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to, and including, 8.7.3. This makes it possible for authenticated attackers,…

Versions affectées

*-8.7.3

Correctif

8.7.4

Publication

04/09/2024

CVE-2024-7381 Moyenne · 5,3
Geo Controller

Geo Controller <= 8.6.9 – Missing Authorization to Unauthenticated Shortcode Execution

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers…

Versions affectées

*-8.6.9

Correctif

8.7.0

Publication

04/09/2024

Vulnérabilité Moyenne · 6,1
Geo Controller

WordPress Geolocation Plugin – CF Geo Plugin <= 7.13.11 – Reflected Cross-Site Scripting

The WordPress Geolocation Plugin – CF Geo Plugin Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘license_key’ parameter in versions up to, and including, 7.13.11 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-7.13.11

Correctif

7.13.12

Publication

31/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités