Extension WordPress
Vulnérabilités Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
Cette page rassemble les failles publiées pour Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Molongui Authorship – Author Boxes, Guest Authors & Co-Authors for WordPress
6 fiches
Molongui <= 4.7.7 – Authenticated (Author+) Insecure Direct Object Reference
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.7.7 due to missing validation on a user controlled…
*-4.7.7
4.7.8
28/03/2024
Molongui <= 4.7.7 – Authenticated (Author+) Stored Cross-Site Scripting
The Molongui plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above,…
*-4.7.7
4.7.8
25/03/2024
Author Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 – Information Exposure via ma_debug
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.4 via the 'ma_debu' parameter. This makes it possible for…
*-4.7.4
4.7.5
16/01/2024
Molongui <= 4.7.3 – Missing Authorization
The Molongui plugin for WordPress is vulnerable to unauthorized modification and access of data due to missing capability checks on the authorship_export_options() and authorship_save_options() functions hooked via AJAX in versions up to, and including, 4.7.3. This makes it…
*-4.7.3
4.7.4
26/12/2023
Molongui <= 4.6.19 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.6.19 due to insufficient input sanitization and…
*-4.6.19
4.6.20
28/11/2023
Molongui <= 4.6.19 – Reflected Cross-Site Scripting
The Molongui plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in versions up to, and including, 4.6.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.6.19
4.6.20
26/07/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.