Extension WordPress
Vulnérabilités Post Meta Data Manager
Cette page rassemble les failles publiées pour Post Meta Data Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post Meta Data Manager
6 fiches
Post Meta Data Manager <= 1.4.4 – Authentciated (Admin+) Multisite Privilege Escalation
The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is due to the plugin not properly verifying the existence of a multisite installation prior…
*-1.4.4
Non indiqué
07/03/2025
Post Meta Data Manager <= 1.2.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.2.3
1.3.0
01/07/2024
Post Meta Data Manager <= 1.2.1 – Cross-Site Request Forgery to Post, Term, and User Meta Deletion
The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions. This makes…
*-1.2.1
1.2.2
20/11/2023
Post Meta Data Manager <=1.2.0 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible…
*-1.2.0
1.2.1
27/10/2023
Post Meta Data Manager <=1.2.0 – Missing Authorization to User, Term, and Post Meta Deletion
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it…
*-1.2.0
1.2.1
27/10/2023
Post Meta Data Manager <= 1.2.0 – Missing Authorization to Post, Term, and User Meta Deletion
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions hooked via nopriv AJAX actions in all versions up…
*-1.2.0
1.2.1
20/10/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.