Extension WordPress
Vulnérabilités Patreon WordPress
Cette page rassemble les failles publiées pour Patreon WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Patreon WordPress
10 fiches
Patreon WordPress <= 1.9.1 – Missing Authorization
The Patreon WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to perform an…
*-1.9.1
1.9.2
24/01/2025
Patreon WordPress <= 1.9.0 – Protection Mechanism Bypass
The Patreon WordPress plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.9.0. This is due to plugin allowing a bypass when a specific header was supplied. This makes it possible…
*-1.9.0
1.9.1
28/06/2024
Patreon WordPress <= 1.8.7 – Cross-Site Request Forgery
The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on several functions in the ~/classes/patreon_wordpress.php file. This makes it…
*-1.8.7
1.8.8
07/11/2023
Patreon WordPress <= 1.8.1 – Authenticated Stored Cross-Site Scripting
The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.8.1 due to insufficient privilege handling. This makes it possible for high-privilege users attackers to inject arbitrary web scripts that execute…
[*, 1.8.2)
1.8.2
20/02/2022
Patreon WordPress <= 1.7.0 – Reflected Cross-Site Scripting
The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a…
[*, 1.7.2)
1.7.2
26/03/2021
Patreon WordPress <= 1.6.9 – Cross-Site Request Forgery
The Patreon WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.9. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles…
[*, 1.7.0)
1.7.0
26/03/2021
Patreon WordPress <= 1.7.0 – Reflected Cross-Site Scripting
The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on…
[*, 1.7.2)
1.7.2
26/03/2021
Patreon WordPress <= 1.6.9 – Cross-Site Request Forgery
The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.
*-1.6.9
1.7.0
26/03/2021
Patreon WordPress < 1.7.0 – Local File Disclosure
The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like…
[*, 1.7.0)
1.7.0
26/03/2021
Patreon WordPress < 1.2.2 – PHP Object Injection
The Patreon WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.2 via deserialization of untrusted input via the 'state' parameter. This makes it possible for attackers to inject a PHP…
[*, 1.2.2)
1.2.2
23/11/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.