Extension WordPress
Vulnérabilités Plausible Analytics
Cette page rassemble les failles publiées pour Plausible Analytics, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Plausible Analytics
3 fiches
Plausible Analytics <= 1.3.3 – Reflected Cross-Site Scripting via page-url
The Plausible Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page-url parameter in versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.3.3
1.3.4
16/08/2023
Plausible Analytics <= 1.2.3 – Missing Authorization
The Plausible Analytics plugin is vulnerable to unauthorized setting changes in versions up to, and including, 1.2.3 due to an improperly configured capability and nonce check on the save_admin_settings() function. This could be exploited by any authenticated user,…
*-1.2.3
1.2.4
27/05/2022
Plausible Analytics <= 1.2.2 – Stored Cross-Site Scripting
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) in PlausibleHQ Plausible Analytics (WordPress plugin)
*-1.2.2
1.2.3
07/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.