Extension WordPress
Vulnérabilités IgniteUp – Coming Soon and Maintenance Mode
Cette page rassemble les failles publiées pour IgniteUp – Coming Soon and Maintenance Mode, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de IgniteUp – Coming Soon and Maintenance Mode
5 fiches
IgniteUp – Coming Soon and Maintenance Mode <= 3.4.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't have the unfiltered_html capability, which could lead to Stored Cross-Site Scripting issues
*-3.4.1
3.4.2
13/04/2022
IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 – Information Disclosure
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
*-3.4.0
3.4.1
10/11/2019
IgniteUp – Coming Soon and Maintenance Mode <= 3.4.0 – Cross-Site Request Forgery
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
*-3.4.0
3.4.1
10/11/2019
IgniteUp – Coming Soon and Maintenance Mode <= 3.4 – Unauthenticated Arbitrary File Deletion
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
[*, 3.4.1)
3.4.1
10/11/2019
IgniteUp – Coming Soon and Maintenance Mode <= 3.4 – Stored Cross-Site Scripting
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
[*, 3.4.1)
3.4.1
10/11/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.