Extension WordPress

Vulnérabilités Under Construction / Maintenance Mode from Acurax

Cette page rassemble les failles publiées pour Under Construction / Maintenance Mode from Acurax, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
0Critiques
0Avec correctif
6,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Under Construction / Maintenance Mode from Acurax

4 fiches

CVE-2024-35749 Moyenne · 5,3
Under Construction / Maintenance Mode from Acurax

Under Construction / Maintenance Mode from Acurax <= 2.6 – Unauthenticated IP Spoofing

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.6 due to insufficient IP address validation and/or use of user-supplied HTTP headers as…

Versions affectées

*-2.6

Correctif

Non indiqué

Publication

06/06/2024

CVE-2024-1476 Moyenne · 5,3
Under Construction / Maintenance Mode from Acurax

Under Construction / Maintenance Mode from Acurax <= 2.6 – Information Exposure

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain…

Versions affectées

*-2.6

Correctif

Non indiqué

Publication

27/02/2024

CVE-2023-6922 Moyenne · 4,3
Under Construction / Maintenance Mode from Acurax

Under Construction / Maintenance Mode from Acurax <= 2.6 – Authenticated (Subscriber+) Sensitive Information Exposure

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow authenticated attackers to extract sensitive data such…

Versions affectées

*-2.6

Correctif

Non indiqué

Publication

27/02/2024

CVE-2023-39926 Moyenne · 6,1
Under Construction / Maintenance Mode from Acurax

Under Construction / Maintenance Mode from Acurax <= 2.6 – Unauthenticated Cross-Site Scripting

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parameter in versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.6

Correctif

Non indiqué

Publication

07/11/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités