Extension WordPress

Vulnérabilités Security Optimizer – The All-In-One Protection Plugin

Cette page rassemble les failles publiées pour Security Optimizer – The All-In-One Protection Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Security Optimizer – The All-In-One Protection Plugin

5 fiches

CVE-2024-38774 Moyenne · 4,3
Security Optimizer – The All-In-One Protection Plugin

Security Optimizer – The All-In-One Protection Plugin <= 1.5.0 – Missing Authorization via hide_notice()

The Security Optimizer – The All-In-One Protection Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the hide_notice() function in versions up to, and including, 1.5.0. This makes it…

Versions affectées

*-1.5.0

Correctif

1.5.1

Publication

19/07/2024

CVE-2023-0234 Élevée · 7,2
Security Optimizer – The All-In-One Protection Plugin

SiteGround Security <= 1.3.0 – Authenticated (Administrator+) SQL Injection

The SiteGround Security plugin for WordPress is vulnerable to blind SQL Injection via some if its filtering and paging parameters in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

13/01/2023

CVE-2022-0993 Élevée · 8,1
Security Optimizer – The All-In-One Protection Plugin

SiteGround Security <= 1.2.5 – Authorization Weakness to Authentication Bypass

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success.…

Versions affectées

*-1.2.5

Correctif

1.2.6

Publication

07/04/2022

CVE-2022-0992 Critique · 9,8
Security Optimizer – The All-In-One Protection Plugin

SiteGround Security <= 1.2.5 – Authentication Bypass via 2FA Setup

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure…

Versions affectées

*-1.2.5

Correctif

1.2.6

Publication

06/04/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités