Extension WordPress
Vulnérabilités ImageRecycle pdf & image compression
Cette page rassemble les failles publiées pour ImageRecycle pdf & image compression, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ImageRecycle pdf & image compression
15 fiches
ImageRecycle pdf & image compression <= 3.1.16 – Reflected Cross-Site Scripting
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.1.16
3.1.17
10/12/2024
ImageRecycle pdf & image compression <= 3.1.14 – Missing Authorization in Several AJAX Actions
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible…
*-3.1.14
3.1.15
23/08/2024
ImageRecycle pdf & image compression <= 3.1.14 – Cross-Site Request in Several AJAX Actions
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php…
*-3.1.14
3.1.15
23/08/2024
ImageRecycle pdf & image compression <= 3.1.13 – Missing Authorization to Settings Update in stopOptimizeAll
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Missing Authorization to Settings Update in disableOptimization
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disableOptimization function in all versions up to, and including, 3.1.13. This makes it possible…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Cross-Site Request Forgery to Settings Update in disableOptimization
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the disableOptimization function. This makes…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Missing Authorization to Settings Update in optimizeAllOn
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optimizeAllOn function in all versions up to, and including, 3.1.13. This makes it possible…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Cross-Site Request Forgery to Settings Update in stopOptimizeAll
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the stopOptimizeAll function. This makes…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Missing Authorization to Plugin Data Removal in reinitialize
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reinitialize function in all versions up to, and including, 3.1.13. This makes it possible…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Cross-Site Request Forgery to Plugin Data Removal in reinitialize
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Cross-Site Request Forgery to Settings Update in enableOptimization
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the enableOptimization function. This makes…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Cross-Site Request Forgery to Settings Update in optimizeAllOn
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the optimizeAllOn function. This makes…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.13 – Missing Authorization to Settings Update in enableOptimization
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization function in all versions up to, and including, 3.1.13. This makes it possible…
*-3.1.13
3.1.14
07/02/2024
ImageRecycle pdf & image compression <= 3.1.10 – Reflected Cross-Site Scripting
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.1.10 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 3.1.11)
3.1.11
11/08/2023
ImageRecycle pdf & image compression <= 3.1.11 – Reflected Cross-Site Scripting
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and 's' parameters in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes…
*-3.1.11
3.1.12
11/08/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.