Extension WordPress
Vulnérabilités DSGVO All in one for WP
Cette page rassemble les failles publiées pour DSGVO All in one for WP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de DSGVO All in one for WP
6 fiches
DSGVO All in one for WP <= 4.9 – Missing Authorization to Authenticated (Subscriber+) Settings Reset
The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while…
*-4.9
5.0
08/07/2026
DSGVO All in one for WP <= 4.6 – Cross-Site Request Forgery to Account Deletion
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This…
*-4.6
4.7
03/02/2025
DSGVO All in one for WP <= 4.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-4.5
4.6
26/08/2024
DSGVO All in one for WP <= 4.3 – Cross-Site Request Forgery
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3. This is due to missing or incorrect nonce validation on the dsgvo_ajax_remove_usr_ip() function. This makes…
*-4.3
4.4
13/03/2024
DSGVO All in one for WP <= 4.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The DSGVO All in one for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dsdvo_customimprinttext’ parameter in versions up to, and including, 4.2 due to insufficient input sanitization and output escaping. This makes it…
*-4.2
4.3
12/09/2022
DSGVO All in one for WP <= 3.9 – Unauthenticated Stored Cross-Site Scripting
The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape some POST parameter submitted before outputting them in the Log page in the administrator dashboard (wp-admin/admin.php?page=dsgvoaiofree-show-log). This…
*-3.9
4.0
07/05/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.