Extension WordPress
Vulnérabilités Easy Social Icons
Cette page rassemble les failles publiées pour Easy Social Icons, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Easy Social Icons
12 fiches
Easy Social Icons <= 3.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Easy Social Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-3.2.4
3.2.5
23/11/2023
Easy Social Icons <= 3.2.4 – Missing Authorization via cnss_save_ajax_order
The Easy Social Icons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cnss_save_ajax_order function in versions up to, and including, 3.2.4. This makes it possible for authenticated attackers,…
*-3.2.4
3.2.5
07/11/2023
Easy Social Icons <= 3.2.2 – Admin+ Cross-Site Scripting
The Easy Social Icons plugin for WordPress was vulnerable to admin+ stored Cross-Site Scripting due to missing sanitization on a few parameters in versions up to, and including, 3.2.2.
*-3.2.2
3.2.3
11/04/2022
Easy Social Icons <= 3.2.0 – Authenticated (Admin+) Cross-Site Scripting and Missing Authorization Checks
The Easy Social Icons plugin for WordPress is vulnerable to Admin+ cross-site scripting and unauthenticated icon deletion in versions up to and including 3.2.0.
*-3.2.0
3.2.1
11/04/2022
Easy Social Icons <= 3.1.4 – Admin+ Cross-Site Scripting
The Easy Social Icons plugin for WordPress is vulnerable to admin-level stored Cross-Site Scripting due to missing sanitization on several variables in versions up to, and including, 3.1.4.
*-3.1.4
3.2.0
11/04/2022
Easy Social Icons <= 3.2.0 – Admin+ Stored Cross-Site Scripting
The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.
[*, 3.2.1)
3.2.1
21/03/2022
Easy Social Icons <= 3.1.3 – Admin+ SQL Injection
The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.
*-3.1.3
3.1.4
08/03/2022
Easy Social Icons <= 3.1.2 – Reflected Cross-Site Scripting
The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.1.2
3.1.3
02/09/2021
Easy Social Icons <= 3.0.8 – Reflected Cross-Site Scripting
The Easy Social Icons plugin
*-3.0.8
3.0.9
01/09/2021
Easy Social Icons <= 3.0.9 – Reflected Cross-Site Scripting
The Easy Social Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.0.9
3.1.0
01/09/2021
Easy Social Icons <= 1.2.3.1 – SQL Injection
The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.2.3.1 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on…
*-1.2.3.1
1.2.4
22/07/2015
Easy Social Icons <= 1.2.2 – Cross-Site Request Forgery to Stored Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an…
*-1.2.2
1.2.3
19/02/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.