Extension WordPress
Vulnérabilités Restaurant & Cafe Addon for Elementor
Cette page rassemble les failles publiées pour Restaurant & Cafe Addon for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Restaurant & Cafe Addon for Elementor
9 fiches
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.5.8
1.6.1
30/04/2026
Restaurant & Cafe Addon for Elementor <= 1.5.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.5.8
1.5.9
11/12/2024
Restaurant & Cafe Addon for Elementor <= 1.5.9 – Authenticated (Contributor+) Post Disclosure
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This…
*-1.5.9
1.6.0
27/11/2024
Restaurant & Cafe Addon for Elementor <= 1.5.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.5.6
1.5.7
31/10/2024
Restaurant & Cafe Addon for Elementor <= 1.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.5.5
1.5.6
24/09/2024
Restaurant & Cafe Addon for Elementor <= 1.5.3 – Missing Authorization via multiple AJAX functions
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 1.5.3. This makes it possible for…
*-1.5.3
1.5.4
16/11/2023
Restaurant & Cafe Addon for Elementor <= 1.5.2 – Cross-Site Request Forgery
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing nonce validation on the rcafe_bw_settings_save_func(), rctl_bw_toggle_submit_func(), rcafe_uw_settings_save_func(), and rctl_uw_toggle_submit_func()…
*-1.5.2
1.5.3
14/11/2023
Restaurant & Cafe Addon for Elementor <= 1.5.2 – Missing Authorization
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the rcafe_bw_settings_save_func(), rctl_bw_toggle_submit_func(), rcafe_uw_settings_save_func(), and rctl_uw_toggle_submit_func() functions all hooked via nopriv AJAX actions in all…
*-1.5.2
1.5.3
14/11/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.4.6)
1.4.6
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.