Extension WordPress

Vulnérabilités Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard

Cette page rassemble les failles publiées pour Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard, leurs plages de versions affectées et les correctifs signalés dans la base locale.

2Vulnérabilités
0Critiques
2Avec correctif
6,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard

2 fiches

CVE-2023-1282 Moyenne · 6,1
Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard

Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard <= 5.0.6.3 and <= 2.11.0 – Reflected Cross-Site Scripting

The Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.0.6.3 or 2.11.0 due to insufficient input sanitization and output…

Versions affectées

2.0-2.11.0, 5.0-5.0.6.3

Correctif

2.11.1, 5.0.6.4

Publication

15/03/2023

CVE-2023-1112 Moyenne · 5,3
Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard

Drag and Drop Multiple File Upload PRO <= 2.10.9 – Directory Traversal

The Drag and Drop Multiple File Upload PRO plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.10.9 due to insufficient restrictions on the path supplied to the upload_dir value. This allows authenticated…

Versions affectées

*-2.10.9

Correctif

2.11.0

Publication

08/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités