Extension WordPress
Vulnérabilités Post List Designer – Category Post, Recent Post, Post List
Cette page rassemble les failles publiées pour Post List Designer – Category Post, Recent Post, Post List, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post List Designer – Category Post, Recent Post, Post List
5 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-3.3.7
3.3.8
30/04/2026
Posts List Designer by Category – List Category Posts Or Recent Posts <= 3.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Posts List Designer by Category – List Category Posts Or Recent Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This…
*-3.3.2
3.3.3
19/01/2024
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.3
3.3.1
18/07/2023
Posts List Designer by Category <= 3.1 – Authenticated (Contributor+) Stored Cross-Site Scriptiong via Shortcode
The Posts List Designer by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-3.1
3.2
06/01/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.1.7)
2.1.7
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.