Extension WordPress
Vulnérabilités Nexter Extension – Security, Performance, Code Snippets & Site Toolkit
Cette page rassemble les failles publiées pour Nexter Extension – Security, Performance, Code Snippets & Site Toolkit, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Nexter Extension – Security, Performance, Code Snippets & Site Toolkit
4 fiches
Nexter Extension – Site Enhancements Toolkit <= 4.4.6 – Unauthenticated PHP Object Injection via 'nxt_unserialize_replace'
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for…
*-4.4.6
4.4.7
20/01/2026
Nexter Extension <= 4.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This…
*-4.4.1
4.4.2
01/12/2025
Nexter Extension <= 2.0.3 – Reflected Cross-Site Scripting via post and post_id
The Nexter Extension plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post’ and 'post_id' parameters in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.0.3
2.0.4
12/10/2023
Nexter Extension <= 2.0.3 – Authenticated(Editor+) Remote Code Execution via metabox
The Nexter Extension plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.3 via the nxt-code-php-snippet metabox. This allows authenticated attackers with editor-level privileges and above to execute code on the server.
*-2.0.3
2.0.4
12/10/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.