Extension WordPress

Vulnérabilités LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

Cette page rassemble les failles publiées pour LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
0Critiques
0Avec correctif
5,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

9 fiches

CVE-2023-4730 Moyenne · 5,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.3 – Missing Authorization via init_endpoint

The LadiApp plugn for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.3. This makes it possible for unauthenticated…

Versions affectées

*-4.3

Correctif

Non indiqué

Publication

16/08/2024

CVE-2023-4629 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp <= 4.4 – Cross-Site Request Forgery via save_config()

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to update the…

Versions affectées

*-4.3

Correctif

Non indiqué

Publication

11/03/2024

CVE-2023-4729 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 – Cross-Site Request Forgery via publish_lp()

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible for…

Versions affectées

*-4.4

Correctif

Non indiqué

Publication

11/03/2024

CVE-2023-4627 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp <= 4.4 – Missing Authorization via save_config()

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including, 4.4. This makes it possible for authenticated attackers with subscriber-level…

Versions affectées

*-4.4

Correctif

Non indiqué

Publication

11/03/2024

CVE-2023-4728 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 – Missing Authorization on publish_lp()

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in versions up to, and including, 4.4. This makes it possible…

Versions affectées

*-4.4

Correctif

Non indiqué

Publication

11/03/2024

CVE-2023-4626 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp <= 4.4 – Missing Authorization via ladiflow_save_hook()

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and including, 4.3. This makes it possible for authenticated attackers with subscriber-level…

Versions affectées

4.3

Correctif

Non indiqué

Publication

11/03/2024

CVE-2023-4731 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… <= 4.4 – Cross-Site Request Forgery via init_endpoint

The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.4

Correctif

Non indiqué

Publication

11/03/2024

CVE-2023-4628 Moyenne · 4,3
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing…

LadiApp <= 4.4 – Cross-Site Request Forgery via ladiflow_save_hook()

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4. This makes it possible for unauthenticated attackers to update the…

Versions affectées

*-4.4

Correctif

Non indiqué

Publication

11/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités