Extension WordPress
Vulnérabilités Classified Listing – AI-Powered Classified ads & Business Directory, page 2
Cette page rassemble les failles publiées pour Classified Listing – AI-Powered Classified ads & Business Directory, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Classified Listing – AI-Powered Classified ads & Business Directory
24 fiches
Classified Listing – Classified ads & Business Directory Plugin <= 3.0.4 – Missing Authorization
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location() rtcl_import_category() functions in all versions up to,…
*-3.0.4
3.0.5
04/04/2024
Classified Listing <= 3.0.4 – Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the…
*-3.0.4
3.0.5
04/04/2024
Classified Listing <= 2.4.5 – Cross-Site Request Forgery via rtcl_ajax_thumbnail_delete
The Classified Listing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.5. This is due to missing or incorrect nonce validation on the rtcl_ajax_thumbnail_delete function. This makes it possible for unauthenticated…
*-2.4.5
2.4.6
05/07/2023
Classima < 2.1.11 – Reflected Cross-Site Scripting
The Classima theme for WordPress is vulnerable to Reflected Cross-site Scripting in versions up to 2.1.11 due to insufficient input sanitization and output escaping on the 'q' parameter. This makes it possible for unauthenticated attackers to inject arbitrary…
[*, 2.2.14)
2.2.14
22/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.