Extension WordPress
Vulnérabilités Insert or Embed Articulate Content into WordPress
Cette page rassemble les failles publiées pour Insert or Embed Articulate Content into WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Insert or Embed Articulate Content into WordPress
9 fiches
Insert or Embed Articulate Content into WordPress <= 4.3000000025 – Authenticated (Editor+) Arbitrary File Upload
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.3000000025. This makes it possible for authenticated attackers,…
*-4.3000000025
4.3000000026
08/04/2025
Insert or Embed Articulate Content into WordPress <= 4.3000000023 – Authenticated (Author+) Arbitrary File Upload
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads through insecure file uploads in a zip archive in all versions up to, and including, 4.3000000023. This makes it possible for…
*-4.3000000023
4.3000000024
24/06/2024
Insert or Embed Articulate Content into WordPress <= 4.3000000023 – Authenticated (Author+) Stored Cross-Site Scripting via Code Injection
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via e-Learning widget file upload in all versions up to, and including, 4.3000000023 due to insufficient input sanitization and output escaping.…
*-4.3000000023
4.3000000025
14/05/2024
Insert or Embed Articulate Content into WordPress <= 4.3000000021 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3000000021 due to insufficient input sanitization and output escaping on…
*-4.3000000021
4.3000000023
19/12/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.3000000020
4.3000000021
18/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 4.3000000016)
4.3000000016
04/03/2022
Insert or Embed Articulate Content into WordPress < 4.29991 – Directory Traversal
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.2999 via the rename_dir. This allows authenticated user with a role as low as subscriber to…
[*, 4.29991)
4.29991
02/07/2019
Insert or Embed Articulate Content into WordPress < 4.2999 – Arbitrary File Upload
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
[*, 4.2999)
4.2999
11/06/2019
Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…
[*, 4.2997)
4.2997
25/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.