Extension WordPress
Vulnérabilités Site Reviews
Cette page rassemble les failles publiées pour Site Reviews, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Site Reviews
14 fiches
Site Reviews <= 8.0.11 – Authenticated (Subscriber+) Sensitive Information Exposure
The Site Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration…
*-8.0.11
8.0.12
26/06/2026
Site Reviews <= 7.2.4 – Unauthenticated Stored Cross-Site Scripting
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-7.2.4
7.2.5
26/02/2025
Site Reviews <= 6.11.8 – IP Address Spoofing to Blocking Bypass
The Site Reviews plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.11.8 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP…
*-6.11.8
7.0.0
08/05/2024
Site Reviews <= 6.11.6 – Authenticated (Author+) Stored Cross-Site Scripting
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.11.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…
*-6.11.6
6.11.7
15/03/2024
Site Reviews <= 6.11.4 – Authenticated(Subscriber+) Stored Cross-Site Scripting via display name
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input sanitization and output escaping. This makes it possible for…
*-6.11.4
6.11.7
11/03/2024
Site Reviews <= 6.10.2 – Missing Authorization
The Site Reviews plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'assignPost' and 'unassignPost' functions in versions up to, and including, 6.10.2. This makes it possible for authenticated…
[*, 6.10.3)
6.10.3
29/08/2023
Site Reviews <= 6.7.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 6.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-6.7.0
6.7.1
05/04/2023
Site Reviews <= 6.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-6.5.1
6.6.0
13/03/2023
Site Reviews <= 6.5.1 – Missing Authorization
The Site Reviews plugin for WordPress is vulnerable to setting modification and information disclosure due to lack of capability checks in a variety of functions, including rollbackPluginAjax, downloadConsole, downloadSystemInfo and exportSettings in versions up to, and including, 6.5.1.…
*-6.5.0
6.6.0
13/03/2023
Site Reviews <= 6.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute
The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attribute(s) in versions up to, and including, 6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-6.5.1
6.6.0
13/03/2023
Site Reviews <= 6.2.0 – Unauthenticated CSV Injection
The Site Reviews plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.2.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these…
*-6.2.0
6.4.0
27/01/2023
Site Reviews <= 5.17.2 – Unauthenticated Stored Cross-Site Scripting
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins…
*-5.17.2
5.17.3
06/12/2021
Site Reviews <= 5.13.0 – Admin+ Stored Cross-Site Scripting
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed
[*, 5.13.1)
5.13.1
09/08/2021
Site Reviews <= 2.15.2 – Cross-Site Scripting
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 2.15.3)
2.15.3
28/05/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.