Extension WordPress
Vulnérabilités Javo Core
Cette page rassemble les failles publiées pour Javo Core, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Javo Core
5 fiches
Javo Core <= 3.0.0.266 – Cross-Site Request Forgery
The Javo Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.0.266. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-3.0.0.266
Non indiqué
26/09/2025
Javo Core <= 3.0.0.266 – Missing Authorization
The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.0.266. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-3.0.0.266
Non indiqué
22/09/2025
Javo Core <= 3.0.0.529 – Unauthenticated Arbitrary Content Deletion
The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.0.529. This makes it possible for unauthenticated attackers to delete arbitrary…
*-3.0.0.529
Non indiqué
26/08/2025
Javo Core <= 3.0.0.266 – Unauthenticated Remote Code Execution
The Javo Core plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.0.0.266. This makes it possible for unauthenticated attackers to execute code on the server.
*-3.0.0.266
Non indiqué
03/08/2025
Javo Core <= 3.0.0.080 – Unauthenticated Privilege Escalation in ajax_signup
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This…
*-3.0.0.080
3.0.0.266
07/03/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.