Extension WordPress
Vulnérabilités HT Event – WordPress Event Manager Plugin for Elementor
Cette page rassemble les failles publiées pour HT Event – WordPress Event Manager Plugin for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de HT Event – WordPress Event Manager Plugin for Elementor
3 fiches
HT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 – Authenticated (Contributor+) Sensitive Information Exposure via HT Event: Sponsor
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for…
*-1.4.7
1.4.8
30/01/2025
HT Event <= 1.4.6 – Reflected Cross-Site Scripting
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it…
*-1.4.6
1.4.7
30/12/2024
HT Event <= 1.4.5 – Cross-Site Request Forgery leading to Arbitrary Plugin Activation
The HT Event plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.5. This is due to missing or incorrect nonce validation on the 'plugin_activation' function. This makes it possible for unauthenticated…
*-1.4.5
1.4.6
28/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.