Extension WordPress

Vulnérabilités Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Cette page rassemble les failles publiées pour Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
5,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

8 fiches

CVE-2025-48242 Moyenne · 4,3
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Legal Pages <= 1.4.5 – Missing Authorization

The Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpwax_legal_page() function in all versions up to,…

Versions affectées

*-1.4.5

Correctif

1.4.6

Publication

19/05/2025

CVE-2024-32451 Informationnelle
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Legal Pages <= 1.4.2 – Cross-Site Request Forgery

The Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the uninstall_reason_submission function. This makes it possible for unauthenticated…

Versions affectées

*-1.4.2

Correctif

1.4.3

Publication

12/04/2024

CVE-2023-47824 Moyenne · 5,4
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Legal Pages <= 1.3.8 – Cross-Site Request Forgery via moveToTrash and fetch_and_insert_template_data

The Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.8. This is due to missing or incorrect nonce validation on the moveToTrash and fetch_and_insert_template_data functions. This makes it possible…

Versions affectées

*-1.3.8

Correctif

1.3.9

Publication

16/11/2023

Vulnérabilité Moyenne · 4,3
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Legal Pages <= 1.3.8 – Missing Authorization

The Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moveToTrash() and fetch_and_insert_template_data() functions hooked…

Versions affectées

*-1.3.8

Correctif

1.3.9

Publication

14/11/2023

CVE-2023-50886 Moyenne · 4,3
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Legal Pages <= 1.3.7 – Missing Authorization on 'deleteLegalTemplate'

The Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deleteLegalTemplate() function in versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with…

Versions affectées

[*, 1.3.8)

Correctif

1.3.8

Publication

18/09/2023

Vulnérabilité Moyenne · 4,3
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Appsero <= 1.2.1 – Missing Authorization

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible…

Versions affectées

*-1.4.1

Correctif

1.4.2

Publication

16/12/2022

CVE-2022-47150 Moyenne · 4,3
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Appsero <= 1.2.0 – Cross-Site Request Forgery

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it…

Versions affectées

*-1.4.1

Correctif

1.4.2

Publication

14/12/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités