Extension WordPress
Vulnérabilités Related Posts for WordPress
Cette page rassemble les failles publiées pour Related Posts for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Related Posts for WordPress
6 fiches
Related Posts for WordPress <= 2.2.1 – Cross-Site Request Forgery
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it…
*-2.2.1
2.2.2
13/03/2024
Related Posts for WordPress <= 2.1.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Related Posts for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_text’ parameter in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-2.1.2
2.1.3
24/10/2022
Related Posts for WordPress <= 2.1.1 – Reflected Cross-Site Scripting
The Related Posts for WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of unsanitized user input when constructing a URL in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers…
*-2.1.1
2.1.2
03/10/2022
Related Posts for WordPress <= 2.0.4 – Stored Cross-Site Scripting
The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high privilege users (admin) to set XSS payloads in them, leading to Stored Cross-Site Scripting issues.
*-2.0.4
2.0.5
17/05/2021
Related Posts for WordPress <= 2.0.3 – Reflected Cross-Site Scripting
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the…
*-2.0.3
2.0.4
15/03/2021
Related Posts for WordPress < 1.8.2 – Reflected Cross-Site Scripting
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, not including, 1.8.2 due to insufficient input sanitization and output escaping. The same vulnerability exists in Related Posts Premium up to,…
[*, 1.8.2)
1.8.2
20/04/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.