Extension WordPress
Vulnérabilités LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…
Cette page rassemble les failles publiées pour LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…
9 fiches
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 – Missing Authorization via init_endpoint
The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated…
*-4.3
Non indiqué
16/08/2024
LadiApp <= 4.4 – Cross-Site Request Forgery via save_config()
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the…
*-4.3
Non indiqué
11/03/2024
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 – Cross-Site Request Forgery via publish_lp()
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for…
*-4.4
Non indiqué
11/03/2024
LadiApp <= 4.4 – Missing Authorization via save_config()
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level…
*-4.4
Non indiqué
11/03/2024
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 – Missing Authorization on publish_lp()
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible…
*-4.4
Non indiqué
11/03/2024
LadiApp <= 4.4 – Missing Authorization via ladiflow_save_hook()
The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level…
4.3
Non indiqué
11/03/2024
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 – Cross-Site Request Forgery via init_endpoint
The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers…
*-4.4
Non indiqué
11/03/2024
LadiApp <= 4.4 – Cross-Site Request Forgery via ladiflow_save_hook()
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to update the…
*-4.4
Non indiqué
11/03/2024
LadiApp <= 4.3 – Missing Authorization
The LadiApp plugin for WordPress is vulnerable to unauthorized access of data, modification of data, or loss of data due to a missing capability check on an unknown function in versions up to, and including, 4.3. This makes…
*-4.3
Non indiqué
28/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.