Extension WordPress

Vulnérabilités Ibtana – WordPress Website Builder

Cette page rassemble les failles publiées pour Ibtana – WordPress Website Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
0Critiques
8Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Ibtana – WordPress Website Builder

9 fiches

CVE-2026-1834 Moyenne · 6,4
Ibtana – WordPress Website Builder

Ibtana – WordPress Website Builder <= 1.2.5.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ive' shortcode in all versions up to, and including, 1.2.5.7 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-1.2.5.7

Correctif

1.2.5.8

Publication

30/03/2026

CVE-2025-59581 Moyenne · 4,3
Ibtana – WordPress Website Builder

Ibtana <= 1.2.5.3 – Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in all versions up to, and including, 1.2.5.3. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.2.5.3

Correctif

1.2.5.4

Publication

22/09/2025

CVE-2025-26891 Moyenne · 6,4
Ibtana – WordPress Website Builder

Ibtana <= 1.2.4.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ibtana plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-1.2.4.9

Correctif

Non indiqué

Publication

24/02/2025

CVE-2024-8282 Moyenne · 6,4
Ibtana – WordPress Website Builder

Ibtana – WordPress Website Builder <= 1.2.4.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all versions up to, and including, 1.2.4.4 due to insufficient input sanitization and…

Versions affectées

*-1.2.4.4

Correctif

1.2.4.5

Publication

01/10/2024

CVE-2024-5541 Moyenne · 5,3
Ibtana – WordPress Website Builder

Ibtana – WordPress Website Builder <= 1.2.3.3 – Unauthenticated reCAPTCHA Settings Update

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' function in all versions up to, and including, 1.2.3.3. This makes it possible…

Versions affectées

*-1.2.3.3

Correctif

1.2.3.4

Publication

17/06/2024

CVE-2023-6684 Moyenne · 6,4
Ibtana – WordPress Website Builder

Ibtana – WordPress Website Builder <= 1.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ive' shortcode in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on 'width' and 'height'…

Versions affectées

*-1.2.2

Correctif

1.2.2.1

Publication

07/12/2023

CVE-2022-4674 Moyenne · 6,4
Ibtana – WordPress Website Builder

Ibtana – WordPress Website Builder <= 1.1.8.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [ive] shortcode in versions up to, and including, 1.1.8.7 due to insufficient input sanitization and output escaping on 'id' user…

Versions affectées

*-1.1.8.7

Correctif

1.1.8.8

Publication

20/12/2022

CVE-2021-25014 Moyenne · 6,4
Ibtana – WordPress Website Builder

Ibtana – WordPress Website Builder <= 1.1.4.7 – Missing Authorization to Stored Cross-Site Scripting

The Ibtana – WordPress Website Builder WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which…

Versions affectées

[*, 1.1.4.9)

Correctif

1.1.4.9

Publication

12/01/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités