Extension WordPress

Vulnérabilités LayerSlider

Cette page rassemble les failles publiées pour LayerSlider, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
1Critiques
9Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de LayerSlider

9 fiches

CVE-2024-4575 Moyenne · 6,4
LayerSlider

LayerSlider 7.11.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via ls_search_form Shortcode

The LayerSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ls_search_form shortcode in version 7.11.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

Versions affectées

7.11.0

Correctif

7.11.1

Publication

22/05/2024

Vulnérabilité Élevée · 8,8
LayerSlider

LayerSlider <= 6.2.0 – Cross-Site Request Forgery

The LayerSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2.0. This is due to missing or incorrect nonce validation on the ls_save_screen_options() function. This makes it possible for authenticated attackers…

Versions affectées

*-6.2.0

Correctif

6.2.1

Publication

28/03/2017

Vulnérabilité Moyenne · 6,5
LayerSlider

LayerSlider <= 4.6.1 – Path Traversal

The LayerSlider plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 4.6.1 via the LayerSlider/editor.php skin parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can…

Versions affectées

*-4.6.1

Correctif

5.2.0

Publication

01/08/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités