Extension WordPress

Vulnérabilités Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

Cette page rassemble les failles publiées pour Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

5 fiches

CVE-2026-25309 Moyenne · 5,3
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.10.1 – Missing Authorization

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-4.10.1

Correctif

4.11.0

Publication

17/03/2026

CVE-2026-25330 Moyenne · 4,3
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

PublishPress Authors <= 4.10.1 – Missing Authorization

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-4.10.1

Correctif

4.11.0

Publication

06/02/2026

CVE-2025-47496 Élevée · 8,8
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

PublishPress Authors <= 4.7.5 – Authenticated (Contributor+) Local File Inclusion

The PublishPress Authors plugin for WordPress is vulnerable to Local File Inclusion via the filterAuthorBoxHtml() function in versions up to, and including, 4.7.5. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…

Versions affectées

*-4.7.5

Correctif

4.7.6

Publication

07/05/2025

CVE-2025-26886 Moyenne · 4,9
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

PublishPress Authors <= 4.7.3 – Authenticated (Administrator+) SQL Injection

The PublishPress Authors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

Versions affectées

*-4.7.3

Correctif

4.7.4

Publication

03/03/2025

CVE-2024-9215 Élevée · 8,8
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors

Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.7.1 – Insecure Direct Object Reference to Authenticated (Author+) Arbitrary User Email Update and Account Takeover

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the…

Versions affectées

*-4.7.1

Correctif

4.7.2

Publication

16/10/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités