Extension WordPress

Vulnérabilités Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Cette page rassemble les failles publiées pour Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier ), leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
1Critiques
8Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

9 fiches

CVE-2025-5092 Moyenne · 6,4
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Multiple Plugins and Themes <= (Various Versions) – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (

Versions affectées

*-9.10.5

Correctif

Non indiqué

Publication

19/11/2025

CVE-2022-4207 Moyenne · 5,5
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Image Hover Effects Ultimate 9.8.1 – 9.8.4 – Authenticated (Admin+) Stored Cross-Site Scripting

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping.…

Versions affectées

9.8.1-9.8.4

Correctif

9.8.5

Publication

11/12/2022

CVE-2022-42459 Élevée · 7,2
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Image Hover Effects Ultimate <= 9.7.1 – Authenticated (Admin+) Arbitrary Options Update

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and including, 9.7.1. This is due to a lack of validation on the settings supplied to the post_oxi_settings() function. This…

Versions affectées

*-9.7.1

Correctif

9.7.2

Publication

25/10/2022

CVE-2022-2935 Moyenne · 6,4
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Image Hover Effects Ultimate <= 9.7.3 – Authenticated Stored Cross-Site Scripting via Media URL

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient…

Versions affectées

*-9.7.3

Correctif

9.8.0

Publication

31/08/2022

CVE-2022-2936 Moyenne · 6,4
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Image Hover Effects Ultimate <= 9.7.3 – Authenticated Stored Cross-Site Scripting via Video Link

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization…

Versions affectées

*-9.7.3

Correctif

9.8.0

Publication

31/08/2022

CVE-2022-2937 Moyenne · 6,4
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Image Hover Effects Ultimate <= 9.7.3 – Authenticated Stored Cross-Site Scripting via Title & Description

The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient…

Versions affectées

*-9.7.3

Correctif

9.8.0

Publication

31/08/2022

CVE-2021-25031 Moyenne · 6,1
Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )

Image Hover Effects Ultimate <= 9.7.0 – Reflected Cross-Site Scripting via effects

The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site…

Versions affectées

*-9.7.0

Correctif

9.7.1

Publication

27/12/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités