Extension WordPress
Vulnérabilités ContentStudio
Cette page rassemble les failles publiées pour ContentStudio, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ContentStudio
8 fiches
ContentStudio <= 1.3.7 – Authenticated (Author+) Arbitrary File Upload
The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level…
*-1.3.7
1.4.0
04/12/2025
ContentStudio <= 1.3.7 – Cross-Site Request Forgery to Settings Update
The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated…
*-1.3.7
1.4.0
04/12/2025
ContentStudio <= 1.3.7 – Missing Authorization
The ContentStudio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-1.3.7
1.4.0
19/06/2025
ContentStudio <= 1.3.5 – Missing Authorization
The ContentStudio plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and…
*-1.3.5
1.3.7
07/05/2025
ContentStudio <= 1.2.5 – Authorization Bypass
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to execute…
*-1.2.5
1.2.6
27/01/2023
ContentStudio <= 1.2.5 – Information Exposure
The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.5. This could allow unauthenticated attackers to obtain a nonce needed for the creation of posts.
*-1.2.5
1.2.6
27/01/2023
ContentStudio <= 1.2.5 – Missing Authorization
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata…
*-1.2.5
1.2.6
06/01/2023
ContentStudio <= 1.1.8 – Missing Authorization
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the cstu_set_token functions in versions up to, and including, 1.1.8. This makes it possible for unauthenticated attackers to set the plugin's…
*-1.1.8
1.1.9
07/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.