Extension WordPress
Vulnérabilités Helpie FAQ , Accordion, Docs & Knowledge Base
Cette page rassemble les failles publiées pour Helpie FAQ , Accordion, Docs & Knowledge Base, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Helpie FAQ , Accordion, Docs & Knowledge Base
5 fiches
Helpie FAQ <= 1.45 – Unauthenticated Sensitive Information Exposure
The FAQ / Accordion / Docs / KB – Helpie WordPress FAQ Accordion plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.45. This makes it possible for unauthenticated attackers…
*-1.45
1.46
22/09/2025
Accordion & FAQ – Helpie WordPress Accordion FAQ Plugin <= 1.27 – Authenticated (Editor+) Stored Cross-Site Scripting
The FAQ / Accordion / Docs – Helpie WordPress FAQ Accordion plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.27 due to insufficient input sanitization and output…
*-1.27
1.28
30/09/2024
Helpie FAQ <= 1.9.8 – Reflected Cross-Site Scripting
The Helpie FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several URLs in versions up to, and including, 1.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-1.9.8
1.9.9
18/04/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.7.7)
1.7.7
04/03/2022
Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…
[*, 0.7.2)
0.7.2
25/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.