Extension WordPress
Vulnérabilités Ibtana – WordPress Website Builder
Cette page rassemble les failles publiées pour Ibtana – WordPress Website Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ibtana – WordPress Website Builder
9 fiches
Ibtana – WordPress Website Builder <= 1.2.5.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user…
*-1.2.5.7
1.2.5.8
30/03/2026
Multiple Plugins and Themes <= (Various Versions) – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (
*-1.2.5.1
1.2.5.2
19/11/2025
Ibtana <= 1.2.5.3 – Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in all versions up to, and including, 1.2.5.3. This makes it possible for authenticated attackers, with…
*-1.2.5.3
1.2.5.4
22/09/2025
Ibtana <= 1.2.4.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ibtana plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-1.2.4.9
Non indiqué
24/02/2025
Ibtana – WordPress Website Builder <= 1.2.4.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all versions up to, and including, 1.2.4.4 due to insufficient input sanitization and…
*-1.2.4.4
1.2.4.5
01/10/2024
Ibtana – WordPress Website Builder <= 1.2.3.3 – Unauthenticated reCAPTCHA Settings Update
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' function in all versions up to, and including, 1.2.3.3. This makes it possible…
*-1.2.3.3
1.2.3.4
17/06/2024
Ibtana – WordPress Website Builder <= 1.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height'…
*-1.2.2
1.2.2.1
07/12/2023
Ibtana – WordPress Website Builder <= 1.1.8.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [ive] shortcode in versions up to, and including, 1.1.8.7 due to insufficient input sanitization and output escaping on 'id' user…
*-1.1.8.7
1.1.8.8
20/12/2022
Ibtana – WordPress Website Builder <= 1.1.4.7 – Missing Authorization to Stored Cross-Site Scripting
The Ibtana – WordPress Website Builder WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which…
[*, 1.1.4.9)
1.1.4.9
12/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.