Extension WordPress
Vulnérabilités Finale Lite – Sales Countdown Timer & Discount for WooCommerce
Cette page rassemble les failles publiées pour Finale Lite – Sales Countdown Timer & Discount for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Finale Lite – Sales Countdown Timer & Discount for WooCommerce
7 fiches
Finale Lite <= 2.20.0 – Reflected Cross-Site Scripting
The Finale Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.20.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.20.0
Non indiqué
28/07/2025
Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer
The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the countdown timer in all versions up to, and including, 2.19.0 due to insufficient input sanitization…
*-2.19.0
2.20.0
11/03/2025
Finale Lite <= 2.18.0 – Cross-Site Request Forgery
The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.18.0. This is due to missing or incorrect nonce validation on…
*-2.18.0
2.18.1
11/04/2024
Finale Lite <= 2.18.0 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation
The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in all versions up to, and including, 2.18.0. This makes it…
*-2.18.0
2.18.1
28/03/2024
NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 – Missing Authorization to Unauthenticated System Information Disclosure
The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the…
*-2.17.0
2.18.0
29/02/2024
Finale Lite <= 2.16.0 – Missing Authorization to Content Deletion
The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on one of its functions in all versions up to, and…
*-2.16.0
2.17.0
31/10/2023
Finale WooCommerce Sale Countdown <= 2.9.0 – Authenticated Arbitrary File Upload
The Finale WooCommerce Sale Countdown plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the xl_maybe_push_support_request function in versions up to, and including, 2.9.0. This makes it possible for authenticated attackers…
[*, 2.9.1)
2.9.1
29/05/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.