Extension WordPress
Vulnérabilités LWS Affiliation
Cette page rassemble les failles publiées pour LWS Affiliation, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LWS Affiliation
4 fiches
LWS Affiliation <= 2.3.6 – Cross-Site Request Forgery
The LWS Affiliation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-2.3.6
Non indiqué
22/09/2025
LWS Affiliation <= 2.3.4 – Missing Authorization
The LWS Affiliation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level access…
*-2.3.4
2.3.5
26/08/2024
LWS Affiliation <= 2.2.6 – Unauthenticated Remote/Local File Inclusion
The LWS Affiliation plugin for WordPress is vulnerable to Remote/Local File Inclusion in versions up to, and including, 2.2.6 via the 'path' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided…
*-2.2.6
2.3
24/07/2023
LWS Plugins <= (Various Versions) – Missing Authorization Checks
Several LWS Plugins for WordPress are vulnerable to authorization bypass due to making admin settings pages available to users with read access (LWS Affiliation in versions up to, and including, 2.1; LWS Optimize in versions up to, and…
*-2.1
2.2
12/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.