Extension WordPress
Vulnérabilités Social Proof Popups & Real-Time Notifications – Herd Effects
Cette page rassemble les failles publiées pour Social Proof Popups & Real-Time Notifications – Herd Effects, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Social Proof Popups & Real-Time Notifications – Herd Effects
6 fiches
Herd Effects <= 6.2.1 – Cross-Site Request Forgery to Settings Update
The Herd Effects plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.2.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-6.2.1
6.2.2
24/01/2025
Herd Effects – fake notifications and social proof plugin <= 5.2.6 – Cross-Site Request Forgery
The Herd Effects – fake notifications and social proof plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.6. This is due to missing or incorrect nonce validation on the…
*-5.2.6
5.2.7
11/04/2024
Herd Effects <= 5.2.3 – Cross-Site Request Forgery to Effect Deletion
The Herd Effects for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation when deleting effects. This makes it possible for unauthenticated attackers to…
*-5.2.3
5.2.4
21/08/2023
Herd Effects <= 5.2.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Herd Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
[*, 5.2.3)
5.2.3
21/08/2023
Multiple Wow-Company Plugins (Various Versions) — Reflected Cross-Site Scripting via 'page' parameter
Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-5.2.1
5.2.2
22/05/2023
Herd Effects <= 5.2 – Local File Inclusion
Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin
*-5.2
5.2.1
16/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.