Extension WordPress
Vulnérabilités ClimateClick: Climate Action for all
Cette page rassemble les failles publiées pour ClimateClick: Climate Action for all, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ClimateClick: Climate Action for all
3 fiches
CO2ok: carbon offsetting for e-commerce <= 1.0.9.21 – Cross-Site Scripting
The plugin CO2ok: carbon offsetting for e-commerce is vulnerable to Cross-Site Scripting via the several parameters in versions up to, and including, 1.0.9.21 due to insufficient input sanitization and output escaping. This makes it possible for attackers to…
*-1.0.9.21
1.0.9.22
31/05/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
*-1.0.9.21
1.0.9.22
04/03/2022
Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…
*-1.0.9.21
1.0.9.22
25/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.