Extension WordPress
Vulnérabilités DELUCKS SEO
Cette page rassemble les failles publiées pour DELUCKS SEO, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de DELUCKS SEO
7 fiches
DELUCKS SEO <= 2.7.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.7.0
Non indiqué
22/09/2025
DELUCKS SEO <= 2.6.0 – Authenticated (Subscriber+) Privilege Escalation
The DELUCKS SEO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges.
*-2.6.0
2.6.1
31/07/2025
DELUCKS SEO <= 2.5.9 – Missing Authorization
The DELUCKS SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.9. This makes it possible for unauthenticated attackers to perform an…
*-2.5.9
2.6.0
19/06/2025
DELUCKS SEO <= 2.5.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-2.5.9
2.6.0
07/05/2025
DELUCKS SEO <= 2.5.8 – Authenticated (Subscriber+) Arbitrary File Read
The DELUCKS SEO plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files…
*-2.5.8
Non indiqué
05/12/2024
DELUCKS SEO <= 2.5.4 – Missing Authorization
The DELUCKS SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_reason() function in versions up to, and including, 2.5.4. This makes it possible for unauthenticated attackers to…
*-2.5.4
2.5.5
29/03/2024
DELUCKS SEO < 2.1.8 – Stored Cross Site Scripting
The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that had no capability checks in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes…
*-2.1.7
2.1.8
21/09/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.