Extension WordPress
Vulnérabilités ImagePress – Image Gallery
Cette page rassemble les failles publiées pour ImagePress – Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ImagePress – Image Gallery
3 fiches
ImagePress – Image Gallery <= 1.2.2 – Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.2.2
1.3.0
11/10/2024
ImagePress – Image Gallery <= 1.2.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update
The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2. This…
*-1.2.2
1.3.0
11/10/2024
ImagePress – Image Gallery <= 1.2.2 – Cross-Site Request Forgery to Plugin Settings Update
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the 'imagepress_admin_page' function. This makes it…
*-1.2.2
1.3.0
11/10/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.