Extension WordPress
Vulnérabilités CM Search And Replace – Optimize content edits with a powerful search and replace tool
Cette page rassemble les failles publiées pour CM Search And Replace – Optimize content edits with a powerful search and replace tool, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CM Search And Replace – Optimize content edits with a powerful search and replace tool
7 fiches
CM On Demand Search And Replace <= 1.5.2 – Cross-Site Request Forgery
The CM Search And Replace – Optimize content edits with a powerful search and replace tool plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing…
*-1.5.2
1.5.3
14/08/2025
CM On Demand Search And Replace <= 1.5.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The CM On Demand Search And Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.5.2
1.5.3
14/08/2025
CM On Demand Search And Replace <= 1.5.4 – Missing Authorization
The CM On Demand Search And Replace plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.4. This makes it possible for authenticated attackers,…
*-1.5.4
Non indiqué
30/06/2025
Multiple Plugins <= (Various Versions) – Reflected Cross-Site Scripting via cminds_free_guide Shortcode
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-1.4.2
1.4.3
25/11/2024
CM WordPress Search And Replace Plugin <= 1.3.8 – Cross-Site Request Forgery to Plugin Setting Reset
The CM WordPress Search And Replace Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing or incorrect nonce validation on the 'cmodsar_settings' page. This…
*-1.3.8
1.3.9
22/07/2024
CM On Demand Search And Replace <= 1.3.0 – Cross-Site Request Forgery
The CM On Demand Search And Replace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the ajaxUpdateReplacement, ajaxDeleteReplacement, and ajaxAddReplacement functions called…
*-1.3.0
1.3.1
09/05/2023
CM On Demand Search And Replace <= 1.3.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The CM On Demand Search And Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.3.0
1.3.1
28/04/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.