Extension WordPress

Vulnérabilités CP Image Store with Slideshow

Cette page rassemble les failles publiées pour CP Image Store with Slideshow, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
1Critiques
4Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CP Image Store with Slideshow

4 fiches

CVE-2026-0684 Moyenne · 4,3
CP Image Store with Slideshow

CP Image Store with Slideshow <= 1.1.9 – Missing Authorization to Authenticated (Contributor+) Arbitrary Product Import

The CP Image Store with Slideshow plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9 due to a logic error in the 'cpis_admin_init' function's permission check. This makes it possible for…

Versions affectées

*-1.1.9

Correctif

1.2.0

Publication

12/01/2026

Vulnérabilité Élevée · 7,5
CP Image Store with Slideshow

CP Image Store with Slideshow < 1.0.6 – Arbitrary File Download

The CP Image Store with Slideshow plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.6 via the cpis_download_file function. This allows unauthenticated attackers to download arbitrary files from the server, which can contain sensitive information.

Versions affectées

[*, 1.0.6)

Correctif

1.0.6

Publication

10/07/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités