Extension WordPress
Vulnérabilités Orange Form
Cette page rassemble les failles publiées pour Orange Form, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Orange Form
2 fiches
Orange Form <= 1.0.1 – Cross-Site Request Forgery
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers…
*-1.0.1
Non indiqué
29/12/2021
Orange Form <= 1.0.1 – Cross-Site Request Forgery
In the Orange Form WordPress plugin through 1.0.1, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of…
*-1.0.1
Non indiqué
29/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.