Extension WordPress
Vulnérabilités IMPress for IDX Broker
Cette page rassemble les failles publiées pour IMPress for IDX Broker, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de IMPress for IDX Broker
5 fiches
IMPress for IDX Broker <= 3.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The IMPress for IDX Broker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-3.2.3
3.2.4
31/03/2025
IMPress for IDX Broker <= 3.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The IMPress for IDX Broker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-3.2.2
3.2.3
16/09/2024
IMPress for IDX Broker <= 3.0.5 – Reflected Cross-Site Scripting
The IMPress for IDX Broker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘leadID’ parameter in versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 3.0.6)
3.0.6
18/10/2021
IMPress for IDX Broker <= 2.6.1 – Authenticated Stored Cross-Site Scripting
Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subscriber-level) permissions to save arbitrary JavaScript in the plugin's settings panel via the idx_update_recaptcha_key AJAX action and a crafted idx_recaptcha_site_key parameter,…
[*, 2.6.2)
2.6.2
26/03/2020
IMPress for IDX Broker <= 2.6.1 – Authenticated Arbitrary Post Creation, Modification, and Deletion
An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in user (with the Subscriber role) to permanently delete arbitrary posts and pages, create new posts with arbitrary subjects, and…
[*, 2.6.2)
2.6.2
26/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.