Extension WordPress
Vulnérabilités WP-FormAssembly
Cette page rassemble les failles publiées pour WP-FormAssembly, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-FormAssembly
5 fiches
WP-FormAssembly <= 2.0.11 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.0.11
3.0.0
17/02/2025
WP-FormAssembly <= 2.0.10 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
*-2.0.10
2.0.11
16/04/2024
WP-FormAssembly <= 2.0.8 – Limited Server Side Request Forgery via 'formassembly' shortcode
The WP-FormAssembly plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.0.8 via the 'formassembly' shortcode. This can allow authenticated attackers with subscriber-level privileges or above to make web requests to arbitrary…
[*, 2.0.9)
2.0.9
02/05/2023
WP-FormAssembly <= 2.0.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-2.0.7
2.0.8
18/04/2023
WP-FormAssembly <= 2.0.5 – Authenticated (Contributor+) Arbitrary File Read
The WP-FormAssembly plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.0.5. This is due to insufficient controls on defining file paths on the fa_add() function. This makes it possible for contributor-level…
*-2.0.5
2.0.6
23/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.