Extension WordPress
Vulnérabilités Simple:Press Forum
Cette page rassemble les failles publiées pour Simple:Press Forum, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple:Press Forum
10 fiches
Simple:Press <= 6.10.5 – Missing Authorization
The Simple:Press Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sp_move_post() function in all versions up to, and including, 6.11.5. This makes it possible for unauthenticated attackers to move…
*-6.11.5
6.11.6
31/03/2025
Simple:Press <= 6.10.12 – Cross-Site Request Forgery to Unauthorized Post Editing
The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.12. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for…
*-6.10.12
6.10.13
28/02/2025
Simple:Press Forum <= 6.10.11 – Reflected Cross-Site Scripting
The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-6.10.11
6.10.12
29/01/2025
Simple:Press Forum <= 6.10.10 – Reflected Cross-Site Scripting via msearch
The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msearch' parameter in all versions up to, and including, 6.10.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-6.10.10
6.10.11
17/01/2025
Simple:Press <= 6.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Signatures
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and including, 6.8 due to insufficient input sanitization and…
*-6.8
6.8.1
29/11/2022
Simple:Press <= 6.8 – Reflected Cross-Site Scripting via Cookie Value
The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping. This makes…
*-6.8
6.8.1
29/11/2022
Simple:Press <= 6.8 – Unauthenticated Stored Cross-Site Scripting via Forum Replies
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting…
*-6.8
6.8.1
29/11/2022
Simple:Press <= 6.8 – Authenticated (Subscriber+) Path Traversal to Arbitrary File Deletion
The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions…
*-6.8
6.8.1
29/11/2022
Simple:Press <= 6.8 – Authenticated (Admin+) Path Traversal to Arbitrary File Modification
The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.8 via the 'file' parameter which does not properly restrict files to be edited in the context of the plugin. This…
*-6.8
6.8.1
29/11/2022
Simple:Press – WordPress Forum Plugin <= 6.6.0 – Arbitrary File Upload
The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to…
[*, 6.6.1)
6.6.1
25/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.