Extension WordPress
Vulnérabilités WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
Cette page rassemble les failles publiées pour WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
4 fiches
WPCode <= 2.3.5 – Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost
The WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom…
*-2.3.5
2.3.6
26/05/2026
WPCode <= 2.0.13 – Unauthenticated Reflected Cross-Site Scripting via Tag Filter Links
The WPCode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via tag filter links in versions up to, and including 2.0.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.0.13
2.0.13.1
17/07/2023
WPCode <= 2.0.8 – Cross-Site Request Forgery
The WPCode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.8. This is due to missing or incorrect nonce validation on the maybe_delete_log function. This makes it possible for unauthenticated attackers…
*-2.0.8
2.0.9
03/04/2023
WPCode <= 2.0.6 – Missing Authorization to Sensitive Key Disclosure/Update
The WPCode plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the ajax_auth_url, store_auth_key, and delete_auth functions in versions up to, and including, 2.0.6. This makes it possible…
*-2.0.6
2.0.7
09/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.