Extension WordPress
Vulnérabilités Pz-LinkCard
Cette page rassemble les failles publiées pour Pz-LinkCard, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Pz-LinkCard
7 fiches
Pz-LinkCard <= 2.5.8.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.5.8.1
Non indiqué
17/04/2026
Pz-LinkCard <= 2.5.6 – Authenticated (Contributor+) Server-Side Request Forgery
The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations…
*-2.5.6
2.5.7
23/09/2025
Pz-LinkCard <= 2.5.2 – Reflected Cross-Site Scripting
The Pz-LinkCard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.5.2
2.5.3
07/03/2024
Pz-LinkCard <= 2.5.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-2.5.2
2.5.3
07/03/2024
Pz-LinkCard <= 2.5.2 – Sever-Side Request Forgery
The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.2 via shortcode. This makes it possible for authenticated attackers, with contributor access or higher, to make web requests to…
*-2.5.2
2.5.3
07/03/2024
Pz-LinkCard <= 2.5.2 – Cross-Site Request Forgery via page_cacheman
The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the page_cacheman function. This makes it possible for unauthenticated attackers…
*-2.5.2
2.5.3
14/11/2023
Pz-LinkCard <= 2.4.5.1 – Reflected Cross-Site Scripting
The Pz-LinkCard plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute…
*-2.4.5.1
2.4.5.2
01/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.