Extension WordPress
Vulnérabilités Login With Ajax – Fast Logins, 2FA, Redirects
Cette page rassemble les failles publiées pour Login With Ajax – Fast Logins, 2FA, Redirects, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Login With Ajax – Fast Logins, 2FA, Redirects
6 fiches
Login With Ajax <= 4.1 – Cross-Site Request Forgery to Notice Dismissal
The Login With Ajax plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1. This is due to missing or incorrect nonce validation on the dismiss_admin_notice() function. This makes it possible for…
*-4.1
4.2
10/04/2024
Login With Ajax <= 4.1 – Missing Authorization
The Login With Ajax plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 4.1. This makes it possible for authenticated attackers, with subscriber-level…
*-4.1
4.2
07/12/2023
Login With Ajax <= 3.1.6 – Cross-Site Scripting
The Login With Ajax plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts…
*-3.1.6
3.1.7
11/04/2017
Login With Ajax < 3.1 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
[*, 3.1)
3.1
06/05/2013
Login With Ajax <= 3.0.4 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter in a lostpassword action to wp-login.php.
*-3.0.4
3.0.4.1
18/05/2012
Login With Ajax < 3.0.4.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter.
[*, 3.0.4.1)
3.0.5
07/05/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.