Extension WordPress
Vulnérabilités g-FFL Cockpit
Cette page rassemble les failles publiées pour g-FFL Cockpit, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de g-FFL Cockpit
2 fiches
g-FFL Cockpit <= 1.7.1 – Improper Authorization to Unauthenticated Product Deletion
The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for…
*-1.7.1
1.8.0
05/12/2025
g-FFL Cockpit <= 1.7.1 – Missing Authorization to Unauthenticated Information Exposure
The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for…
*-1.7.1
1.8.0
05/12/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.