Extension WordPress
Vulnérabilités Dynamics 365 Integration
Cette page rassemble les failles publiées pour Dynamics 365 Integration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Dynamics 365 Integration
6 fiches
Dynamics 365 Integration <= 1.3.23 – Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and…
*-1.3.23
1.3.24
03/01/2025
Dynamics 365 Integration <= 1.3.17 – Unauthenticated Sensitive Information Exposure
The Dynamics 365 Integration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.17 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information…
*-1.3.17
1.3.18
07/05/2024
Dynamics 365 Integration <= 1.3.13 – Missing Authorization via init
The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init function in versions up to, and including, 1.3.13. This makes it possible for authenticated attackers…
*-1.3.13
1.3.14
06/04/2023
Dynamics 365 Integration <= 1.3.12 – Missing Authorization via wp_ajax_wpcrm_log & wp_ajax_wpcrm_log_verbosity
The Dynamics 365 Integration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_wpcrm_log & wp_ajax_wpcrm_log_verbosity functions in versions up to, and including, 1.3.12. This makes it possible for…
*-1.3.12
1.3.13
15/03/2023
Dynamics 365 Integration <= 1.3.12 – Cross-Site Request Forgery via wp_ajax_wpcrm_log_verbosity
The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log_verbosity' AJAX action. This makes it possible for…
*-1.3.12
1.3.13
14/03/2023
Dynamics 365 Integration <= 1.3.12 – Cross-Site Request Forgery via wp_ajax_wpcrm_log
The Dynamics 365 Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.12. This is due to missing or incorrect nonce validation on 'wp_ajax_wpcrm_log' AJAX action. This makes it possible for…
*-1.3.12
1.3.13
13/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.