Extension WordPress
Vulnérabilités File Manager for Google Drive – Integrate Google Drive
Cette page rassemble les failles publiées pour File Manager for Google Drive – Integrate Google Drive, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de File Manager for Google Drive – Integrate Google Drive
14 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.4.9
1.5.0
30/04/2026
Integrate Google Drive <= 1.5.6 – Missing Authorization
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with subscriber-level access…
*-1.5.6
Non indiqué
24/01/2026
File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 – Unauthenticated Sensitive Information Exposure
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for…
*-1.5.3
1.5.4
04/11/2025
Integrate Google Drive <= 1.5.2 – Cross-Site Request Forgery
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation…
*-1.5.2
1.5.3
30/07/2025
Integrate Google Drive <= 1.3.93 – Missing Authorization
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a…
*-1.3.93
1.3.94
03/06/2024
Integrate Google Drive <= 1.3.9 – Missing Authorization
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in versions up to, and including, 1.3.9. This makes it possible for unauthenticated attackers to…
*-1.3.9
1.3.91
22/04/2024
Integrate Google Drive <= 1.3.8 – Missing Authorization
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 1.3.8. This makes it possible for unauthenticated attackers to perform unauthorized…
*-1.3.8
1.3.91
22/04/2024
Integrate Google Drive <= 1.3.8 – Missing Authorization to Unauthenticated Settings Modification and Export
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of…
*-1.3.8
1.3.9
29/03/2024
Integrate Google Drive <= 1.3.3 – Missing Authorization via save_settings
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers,…
*-1.3.3
1.3.4
29/12/2023
Integrate Google Drive <= 1.3.4 – Cross-Site Request Forgery
The Integrate Google Drive plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for…
*-1.3.4
1.3.5
05/12/2023
Integrate Google Drive <= 1.3.2 – Open Redirect via state
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.2.…
*-1.3.2
1.3.3
07/11/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.0.0-1.2.1
1.2.2
18/07/2023
Integrate Google Drive <= 1.1.99 – Missing Authorization via REST API Endpoints
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in versions up to, and including, 1.1.99. This makes it possible for unauthenticated attackers to…
*-1.1.99
1.2.0
12/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.1.0)
1.1.0
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.