Extension WordPress
Vulnérabilités Float menu – awesome floating side menu
Cette page rassemble les failles publiées pour Float menu – awesome floating side menu, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Float menu – awesome floating side menu
5 fiches
Float menu <= 6.1.2 – Cross-Site Request Forgery to Settings Update
The Float menu – awesome floating side menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.2. This is due to missing or incorrect nonce validation on a function. This…
*-6.1.2
6.1.3
27/03/2025
Float menu – awesome floating side menu <= 6.0 – Cross-Site Request Forgery to Menu Deletion
The Float menu – awesome floating side menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0. This is due to missing or incorrect nonce validation on the float-menu function.…
*-6.0
6.0.1
11/04/2024
Float menu <= 5.0.2 – Authenticated(Administrator+) Stored Cross-Site Scripting
The Float menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-5.0.2
5.0.3
19/06/2023
Multiple Wow-Company Plugins (Various Versions) — Reflected Cross-Site Scripting via 'page' parameter
Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-5.0.1
5.0.2
22/05/2023
Float Menu <= 4.3 – Arbitrary Menu Deletion via Cross-Site Request Forgery
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack
*-4.3
4.3.1
24/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.