Extension WordPress
Vulnérabilités Intuitive Custom Post Order
Cette page rassemble les failles publiées pour Intuitive Custom Post Order, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Intuitive Custom Post Order
4 fiches
Intuitive Custom Post Order <= 3.1.4.1 – Authenticated (Admin+) SQL Injection
The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4.1, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in…
*-3.1.4
3.1.5
25/01/2023
Intuitive Custom Post Order <= 3.1.3 – Missing Authorization to Authenticated Settings Change
The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order-sites' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the…
*-3.1.3
3.1.4
25/01/2023
Intuitive Custom Post Order <= 3.1.3 – Cross-Site Request Forgery
The Intuitive Custom Post Order plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing or incorrect nonce validation on the update-menu-order AJAX action. This makes it…
*-3.1.3
3.1.4
24/01/2023
Intuitive Custom Post Order <= 3.1.3 – Missing Authorization to Authenticated Settings Change
The Intuitive Custom Post Order plugin for WordPress is vulnerable to authenticated settings change in versions up to and including 3.1.3 via the 'update-menu-order' AJAX action. This allows authenticated attackers with subscriber privileges or above, to change the…
*-3.1.3
3.1.4
24/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.