Extension WordPress
Vulnérabilités Constant Contact Forms
Cette page rassemble les failles publiées pour Constant Contact Forms, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Constant Contact Forms
4 fiches
Constant Contact Forms <= 2.4.2 – Information Disclosure via Log Files
The Constant Contact Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
*-2.4.2
2.4.3
03/01/2024
Constant Contact Forms <= 2.0.2 – Missing Authorization via constant_contact_privacy_ajax_handler
The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_privacy_ajax_handler function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers,…
*-2.0.2
2.0.3
15/06/2023
Constant Contact Forms <= 1.14.0 – Missing Authorization via constant_contact_optin_ajax_handler
The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_optin_ajax_handler function in versions up to, and including, 1.14.0. This makes it possible for authenticated attackers,…
*-1.14.0
2.0.0
03/06/2023
Constant Contact Forms <= 1.8.7 Editor+ Stored Cross-Site Scripting
Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts…
[*, 1.8.8)
1.8.8
06/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.