Extension WordPress

Vulnérabilités CRM and Lead Management by vcita

Cette page rassemble les failles publiées pour CRM and Lead Management by vcita, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CRM and Lead Management by vcita

5 fiches

CVE-2025-5240 Moyenne · 6,4
CRM and Lead Management by vcita

CRM and Lead Management by vcita <= 2.7.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.7.5

Correctif

2.8.0

Publication

21/07/2025

CVE-2024-13702 Moyenne · 6,4
CRM and Lead Management by vcita

CRM and Lead Management by vcita <= 2.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and 'vCitaSchedulingCalendar' shortcodes in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output…

Versions affectées

*-2.7.4

Correctif

2.7.5

Publication

25/03/2025

CVE-2024-13703 Moyenne · 4,3
CRM and Lead Management by vcita

CRM and Lead Management by vcita <= 2.7.5 – Missing Authorization to Authenticated (Susbcriber+) Widget Toggle

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() function in all versions up to, and including, 2.7.5. This makes it…

Versions affectées

*-2.7.5

Correctif

2.8.0

Publication

12/03/2025

CVE-2023-2405 Moyenne · 6,1
CRM and Lead Management by vcita

CRM and Lead Management by vcita <= 2.7.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible…

Versions affectées

*-2.7.0

Correctif

2.7.1

Publication

02/06/2023

CVE-2023-2404 Moyenne · 6,4
CRM and Lead Management by vcita

CRM and Lead Management by vcita <= 2.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.6.2

Correctif

2.7.0

Publication

02/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités