Extension WordPress
Vulnérabilités Page-list
Cette page rassemble les failles publiées pour Page-list, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Page-list
4 fiches
Page-list <= 6.2 – Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode Attributes
The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function (the [pagelist_ext] / [pagelistext] shortcode) accepting attacker-controlled post_status, post_type, and show_meta_key attributes and…
*-6.2
6.3
05/06/2026
Page-list <= 5.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Page-list plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-5.8
5.9
22/09/2025
Page-list <= 5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Page-list plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-5.6
5.7
30/09/2024
Page-list <= 5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Page-list plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions…
*-5.2
5.3
27/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.