Extension WordPress
Vulnérabilités I Recommend This – Love/Like Button for WordPress Posts
Cette page rassemble les failles publiées pour I Recommend This – Love/Like Button for WordPress Posts, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de I Recommend This – Love/Like Button for WordPress Posts
5 fiches
I Recommend This <= 3.8.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The I Recommend This plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-3.8.3
3.9.0
19/04/2023
I Recommend This <= 3.9.0 – Cross-Site Request Forgery
The I Recommend This plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.9.0. This is due to missing nonce validation on the ajax_callback function. This makes it possible for unauthenticated attackers…
*-3.9.0
3.9.1
22/03/2023
I Recommend This < 3.8.2 – Cross-Site Scripting
The I Recommend This plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
[*, 3.8.2)
3.8.2
11/09/2018
I Recommend This <= 3.7.2 – Authenticated (Subscriber+) SQL Injection via Shortcode
The I Recommend This plugin for WordPress is vulnerable to SQL Injection via the 'post_type' attribute called via the plugin's shortcode in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameter and…
*-3.7.2
3.7.3
24/09/2014
I Recommend This < 3.7.3 – SQL Injection
The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection.
[*, 3.7.3)
3.7.3
24/09/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.