Extension WordPress

Vulnérabilités Leyka

Cette page rassemble les failles publiées pour Leyka, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
1Critiques
10Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Leyka

12 fiches

CVE-2024-49252 Moyenne · 4,3
Leyka

Leyka <= 3.31.6 – Missing Authorization

The Leyka plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the leyka_ajax_get_campaigns_list() function in all versions up to, and including, 3.31.6. This makes it possible for authenticated attackers, with…

Versions affectées

*-3.31.6

Correctif

3.31.7

Publication

14/10/2024

CVE-2024-35683 Moyenne · 5,3
Leyka

Leyka <= 3.31.1 – Missing Authorization

The Leyka plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sendCardCheck function in versions up to, and including, 3.31.1. This makes it possible for unauthenticated attackers to perform a card…

Versions affectées

*-3.31.1

Correctif

3.31.2

Publication

06/06/2024

CVE-2023-4917 Moyenne · 5,3
Leyka

Leyka <= 3.30.7 – Authenticated (Subscriber+) Sensitive Information Exposure

The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank…

Versions affectées

*-3.30.7

Correctif

3.30.7.1

Publication

12/09/2023

CVE-2023-39314 Moyenne · 6,1
Leyka

Leyka <= 3.30.2 – Reflected Cross-Site Scripting

The Leyka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several $_GET parameters in versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.30.2

Correctif

3.30.3

Publication

07/08/2023

CVE-2023-33325 Moyenne · 6,1
Leyka

Leyka <= 3.30.1 – Reflected Cross-Site Scripting

The Leyka plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stage' parameter in versions up to, and including, 3.30.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.30.1

Correctif

3.30.2

Publication

22/05/2023

CVE-2023-27442 Moyenne · 5,4
Leyka

Leyka <= 3.29.2 – Cross-Site Request Forgery

The Leyka plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.29.2. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into…

Versions affectées

*-3.29.2

Correctif

3.30

Publication

03/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités