Extension WordPress
Vulnérabilités ElasticPress
Cette page rassemble les failles publiées pour ElasticPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ElasticPress
9 fiches
ElasticPress <= 5.1.0 – Cross-Site Request Forgery
The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the do_sync function. This makes it possible for unauthenticated…
*-5.1.0
5.1.1
06/06/2024
webpack JS package <= 5.75.0 – Sandbox Bypass
The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic comments. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.
*-4.5.0
4.5.1
11/04/2023
simple-git < 3.15.0 – Remote Code Execution
The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package,…
*-4.4.0
4.4.1
05/12/2022
loader-utils (JS package) < 2.0.3 – Prototype Pollution
The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function parseQuery which could make injecting malicious web scripts possible in some cases.
*-4.3.1
4.4.0
12/10/2022
loader-utils (JS package) < 3.2.1 – Regular Expression Denial of Service
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the resourcePath variable due to insecure usage of regular…
*-4.3.1
4.4.0
11/10/2022
loader-utils (JS package) < 3.2.1 – Regular Expression Denial of Service
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular…
*-4.3.1
4.4.0
11/10/2022
terser (JS Package) < 5.14.2 – Denial of Service
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable…
*-4.2.2
4.3.0
14/07/2022
Moment.js <= 2.29.1 – Directory Traversal
The Javascript library moment.js is vulnerable to a path traversal vulnerability in versions up to, and including, 2.29.1. This makes it possible for attackers to read files outside of the accessed site's root directory leading to information disclosure.
*-4.1.0
4.2.0
05/04/2022
ElasticPress <= 3.5.3 – Cross-Site Request Forgery Bypass
The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers…
*-3.5.3
3.5.4
01/03/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.