Extension WordPress
Vulnérabilités Invite Anyone
Cette page rassemble les failles publiées pour Invite Anyone, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Invite Anyone
6 fiches
Invite Anyone <= 1.4.7 – Reflected Cross-Site Scripting
The Invite Anyone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.4.7
1.4.8
16/08/2024
Invite Anyone <= 1.3.18 – PHP Object Injection
The Invite Anyone plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.18 via deserialization of untrusted input from the 'invite-anyone/trunk/by-email/by-email.php' file. This allows unauthenticated attackers to inject a PHP Object.
*-1.3.18
1.3.19
12/10/2017
Invite Anyone < 1.3.16 – Email Injection
The Invite Anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
[*, 1.3.16)
1.3.16
22/03/2017
Invite Anyone <= 1.3.15 – Improper Input Validation
The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
*-1.3.15
1.3.16
22/03/2017
Invite Anyone < 1.3.16 – Cross-Site Request Forgery
The Invite Anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. The plugin’s setting pages had a vulnerability found in the nonce, which is used to prevent CSRF, but when the settings are saved there was no check…
[*, 1.3.16)
1.3.16
22/03/2017
Invite Anyone <= 1.3.14 – Change of Email Invitation Content
An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social…
[*, 1.3.15)
1.3.15
17/03/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.