Extension WordPress
Vulnérabilités Post to CSV by BestWebSoft
Cette page rassemble les failles publiées pour Post to CSV by BestWebSoft, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post to CSV by BestWebSoft
3 fiches
Post to CSV by BestWebSoft <= 1.4.0 – Authenticated (Author+) CSV Injection
The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code…
*-1.4.0
1.4.1
28/06/2023
Post to CSV by BestWebSoft <= 1.3.8 – Authenticated (Author+) CSV Injection
The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.8. This allows author-level attackers to embed untrusted input into exported CSV files, which can result in code…
*-1.3.8
1.3.9
03/10/2022
Post to CSV by BestWebSoft < 1.3.1 – Reflected Cross-Site Scripting
The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
[*, 1.3.1)
1.3.1
12/04/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.