Extension WordPress
Vulnérabilités REST API TO MiniProgram
Cette page rassemble les failles publiées pour REST API TO MiniProgram, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de REST API TO MiniProgram
5 fiches
REST API TO MiniProgram <= 5.1.2 – Authenticated (Subscriber+) Insecure Direct Object Reference via 'userid' REST API Parameter
The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wechatshop_info_permissions_check) only validating that the supplied 'openid' parameter…
*-5.1.2
Non indiqué
20/03/2026
REST API TO MiniProgram <= 4.7.1 – Cross-Site Request Forgery
The REST API TO MiniProgram plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.1. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-4.7.1
Non indiqué
11/03/2025
REST API TO MiniProgram <= 4.7.1 – Unauthenticated Arbitrary User Email Update and Privilege Escalation via Account Takeover
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that…
*-4.7.1
4.7.6
24/09/2024
REST API TO MiniProgram <= 4.7.1 – Unauthenticated SQL Injection
The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user…
*-4.7.1
5.1
24/09/2024
REST API TO MiniProgram <= 4.7.7 – Authenticated (Subscriber+) Media Attachment Deletion
The REST API TO MiniProgram plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the file_batch_delete_callback() function used to delete uploaded attachments in versions up to, and including,…
*-4.7.7
Non indiqué
25/04/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.