Extension WordPress
Vulnérabilités Contact List – Online Staff Directory & Address Book
Cette page rassemble les failles publiées pour Contact List – Online Staff Directory & Address Book, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contact List – Online Staff Directory & Address Book
5 fiches
Contact List <= 3.0.18 – Authenticated (Contributor+) Stored Cross-Site Scripting via '_cl_map_iframe' Parameter
The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in all versions up to, and including, 3.0.18. This is due to insufficient input sanitization and output escaping when handling the Google…
*-3.0.18
3.0.19
20/03/2026
Contact List – Easy Business Directory, Staff Directory and Address Book Plugin <= 2.9.87 – Missing Authorization to Notice Dismissal
The Contact List – Easy Business Directory, Staff Directory and Address Book Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_notifications() function in versions up to, and…
*-2.9.87
2.9.88
09/05/2024
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
2.9.24-2.9.69
2.9.72
18/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.9.50)
2.9.50
04/03/2022
Contact List – Easy Business Directory, Staff Directory and Address Book Plugin <= 2.9.41 – Reflected Cross-Site Scripting
The Contact List – Easy Business Directory, Staff Directory and Address Book Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘card_height’ parameter in versions up to, and including, 2.9.41 due to insufficient input sanitization and…
*-2.9.41
2.9.42
24/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.