Extension WordPress

Vulnérabilités Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Cette page rassemble les failles publiées pour Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
6,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

6 fiches

CVE-2024-13362 Moyenne · 6,1
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-3.2.7

Correctif

3.2.9

Publication

30/04/2026

CVE-2023-33999 Moyenne · 6,1
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-3.2

Correctif

3.2.1

Publication

18/07/2023

CVE-2022-4974 Moyenne · 6,3
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 2.0.3)

Correctif

2.0.3

Publication

04/03/2022

CVE-2021-24913 Moyenne · 4,3
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Logo Showcase with Slick Slider <= 2.0 – Cross-Site Request Forgery

The Logo Showcase with Slick Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on the lswss_save_attachment_data AJAX action. This makes…

Versions affectées

[*, 2.0.1)

Correctif

2.0.1

Publication

31/01/2022

CVE-2021-24730 Moyenne · 4,3
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid <= 1.2.4 – Cross-Site Request Forgery

The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of…

Versions affectées

[*, 1.2.5)

Correctif

1.2.5

Publication

24/10/2021

CVE-2021-24729 Moyenne · 5,4
Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid <= 1.2.3 – Stored Cross-Site Scripting

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid…

Versions affectées

[*, 1.2.4)

Correctif

1.2.4

Publication

19/10/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités