Extension WordPress
Vulnérabilités GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
Cette page rassemble les failles publiées pour GTM4WP – A Google Tag Manager (GTM) plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
3 fiches
Google Tag Manager for WordPress (GTM4WP) <= 1.15.1 – Stored Cross-Site Scripting via Content Element ID
The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the `gtm4wp-options[scroller-contentid]` parameter found in the `~/public/frontend.php` file which allowed attackers with administrative user access to inject arbitrary web…
*-1.15.1
1.15.2
31/05/2022
Google Tag Manager for WordPress <= 1.15 – Reflected Cross-Site Scripting via Site Search
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to…
*-1.15
1.15.1
19/05/2022
Google Tag Manager for WordPress <= 1.15 – Cross-Site Scripting via Cloudflare Country Code
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $_SERVER['HTTP_CF_IPCOUNTRY'] value in versions up to, and including, 1.15 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.15
1.15.1
12/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.