Extension WordPress
Vulnérabilités Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, page 3
Cette page rassemble les failles publiées pour Easy Digital Downloads – eCommerce Payments and Subscriptions made easy, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
44 fiches
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.9.15 – Stored Cross-Site Scripting
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
[*, 2.9.16)
2.9.16
12/06/2019
Easy Digital Downloads <= 2.5.7 – PHP Object Injection
The Easy Digital Downloads plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.7 via deserialization of untrusted input from cookies and request parameters. This allows unauthenticated attackers to inject a PHP…
*-2.5.7
2.5.8
02/03/2016
Easy Digital Downloads – Simple eCommerce for Selling Digital Files <= 2.3.6 – Cross-Site Scripting
The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.
[*, 1.8.7), [1.9, 1.9.10), [2.0, 2.0.5), [2.1, 2.1.11), [2.2, 2.2.9), [2.3, 2.3.7)
1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, 2.3.7
20/04/2015
Easy Digital Downloads (Various Versions) – Cross-Site Scripting
The Easy Digital Downloads Plugin for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
1.8-1.8.6, 1.9-1.9.9, 2.0-2.0.4, 2.1-2.1.10, 2.2-2.2.8, 2.3-2.3.6
1.8.7, 1.9.10, 2.0.5, 2.1.11, 2.2.9, 2.3.7
20/04/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.