Extension WordPress
Vulnérabilités Modal Window – create popup modal window
Cette page rassemble les failles publiées pour Modal Window – create popup modal window, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Modal Window – create popup modal window
7 fiches
Modal Window <= 6.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via iframeBox Shortcode
The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 6.1.5 due to insufficient input sanitization and output escaping…
*-6.1.5
6.1.6
19/02/2025
Modal Window <= 6.1.4 – Cross-Site Request Forgery to Settings Ipdate
The Modal Window plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-6.1.4
6.1.5
24/01/2025
Modal Window <= 6.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-6.0.3
6.0.4
16/08/2024
Modal Window – create popup modal window <= 5.3.9 – Cross-Site Request Forgery
The Modal Window – create popup modal window plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.9. This is due to missing or incorrect nonce validation on the modal-window page.…
*-5.3.9
5.3.10
11/04/2024
Modal Window – create popup modal window <= 5.3.8 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 5.3.8 due to insufficient input sanitization and output escaping on…
*-5.3.8
5.3.9
20/03/2024
Modal Window <= 5.3.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Modal Window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
*-5.3.5
5.3.6
25/09/2023
Modal Window – create popup modal window <= 5.2.1 – Cross-Site Request Forgery to Remote Code Execution
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
[*, 5.2.2)
5.2.2
05/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.