Extension WordPress
Vulnérabilités Fontiran
Cette page rassemble les failles publiées pour Fontiran, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Fontiran
3 fiches
Fontiran <= 2.1 – Cross-Site Request Forgery
The Fontiran plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the fi_add_rule function. This makes it possible for unauthenticated attackers…
*-2.1
Non indiqué
02/03/2023
Fontiran <= 2.1 – Cross-Site Request Forgery
The Fontiran plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the fi_delete_webfont_php function. This makes it possible for unauthenticated attackers…
*-2.1
Non indiqué
02/03/2023
Fontiran <= 2.1 – Missing Authorization via fi_add_rule and fi_delete_webfont_php
The Fontiran plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the fi_add_rule and fi_delete_webfont_php functions in versions up to, and including, 2.1. This makes it possible for authenticated attackers with…
*-2.1
Non indiqué
15/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.