Extension WordPress
Vulnérabilités Cryptocurrency Widgets – Price Ticker & Coins List
Cette page rassemble les failles publiées pour Cryptocurrency Widgets – Price Ticker & Coins List, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Cryptocurrency Widgets – Price Ticker & Coins List
5 fiches
Cryptocurrency Widgets – Price Ticker & Coins List <= 2.8.0 – Reflected Cross-Site Scripting
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.8.0
2.8.1
16/08/2024
Cryptocurrency Widgets – Price Ticker & Coins List <= 2.6.8 – Missing Authorization
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to unauthorized access due to an insufficient capability check on the ccpw_post_type() function in versions up to, and including, 2.6.8. This makes it possible…
*-2.6.8
2.6.9
13/03/2024
Cryptocurrency Widgets – Price Ticker & Coins List 2.0 – 2.6.5 – Unauthenticated SQL Injection
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of…
2.0-2.6.5
2.6.6
19/01/2024
Cryptocurrency Widgets – Price Ticker & Coins List <= 2.6.2 – Missing Authorization
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on one of its functions in versions up to, and including, 2.6.2. This makes it…
*-2.6.2
2.6.3
04/07/2023
Cool Plugins (Various Versions) – Arbitrary Plugin Installation and Activation
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
*-2.4
2.5.1
04/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.