Extension WordPress
Vulnérabilités Polylang
Cette page rassemble les failles publiées pour Polylang, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Polylang
3 fiches
Polylang <= 3.7.3 – Authenticated (Contributor+) PHP Object Injection
The Polylang plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
*-3.7.3
3.7.4
28/10/2025
Polylang <= 2.5 – Cross-Site Request Forgery
The Polylang plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This is due to missing or incorrect nonce validation on the wp_insert_post_data() function. This makes it possible for unauthenticated attackers…
[*, 2.5.1)
2.5.1
16/01/2019
Polylang <= 1.5.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third…
[*, 1.5.2)
1.5.2
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.