Extension WordPress
Vulnérabilités MainWP Child Reports
Cette page rassemble les failles publiées pour MainWP Child Reports, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MainWP Child Reports
4 fiches
MainWP Child Reports <= 2.2.6 – Missing Authorization to Authenticated (Subscriber+) Information Disclosure via Heartbeat API
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes…
*-2.2.6
2.3
07/04/2026
MainWP Child Reports <= 2.2 – Cross-Site Request Forgery to Arbitrary Options Update
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible…
*-2.2
2.2.1
07/08/2024
MainWP Child Reports <= 2.1.1 – Cross-Site Request Forgery
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the uninstall() function. This makes it possible…
*-2.1.1
2.2
26/04/2024
MainWP Child Reports <= 2.0.7 – Admin+ SQL Injection
The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue
*-2.0.7
2.0.8
20/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.