Extension WordPress
Vulnérabilités Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )
Cette page rassemble les failles publiées pour Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier ), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Image Hover Effects Ultimate ( Image Gallery, Effects, Lightbox, Comparison & Magnifier )
9 fiches
Multiple Plugins and Themes <= (Various Versions) – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library
Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (
*-9.10.5
Non indiqué
19/11/2025
Image Hover Effects Ultimate 9.8.1 – 9.8.4 – Authenticated (Admin+) Stored Cross-Site Scripting
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values that can be added to an Image Hover in versions 9.8.1 to 9.8.4 due to insufficient input sanitization and output escaping.…
9.8.1-9.8.4
9.8.5
11/12/2022
Image Hover Effects Ultimate <= 9.7.1 – Authenticated (Admin+) Arbitrary Options Update
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and including, 9.7.1. This is due to a lack of validation on the settings supplied to the post_oxi_settings() function. This…
*-9.7.1
9.7.2
25/10/2022
Image Hover Effects Ultimate <= 9.7.3 – Authenticated Stored Cross-Site Scripting via Media URL
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image URL value that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient…
*-9.7.3
9.8.0
31/08/2022
Image Hover Effects Ultimate <= 9.7.3 – Authenticated Stored Cross-Site Scripting via Video Link
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient input sanitization…
*-9.7.3
9.8.0
31/08/2022
Image Hover Effects Ultimate <= 9.7.3 – Authenticated Stored Cross-Site Scripting via Title & Description
The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Description values that can be added to an Image Hover in versions up to, and including, 9.7.3 due to insufficient…
*-9.7.3
9.8.0
31/08/2022
Image Hover Effects Ultimate <= 9.7.1 – Reflected Cross-Site Scripting
Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image Hover Effects Ultimate plugin
*-9.7.1
9.7.2
04/05/2022
Image Hover Effects Ultimate <= 9.7.0 – Reflected Cross-Site Scripting via effects
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site…
*-9.7.0
9.7.1
27/12/2021
Image Hover Effects Ultimate <= 9.6.1 – Unauthenticated Arbitrary Options Update
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions
*-9.6.1
9.6.2
15/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.