Extension WordPress
Vulnérabilités Software License Manager
Cette page rassemble les failles publiées pour Software License Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Software License Manager
4 fiches
Software License Manager <= 4.5.0 – Cross-Site Request Forgery leading to Arbitrary Domain Deletion
The Software License Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the del_reistered_domains AJAX action. This makes it possible…
[*, 4.5.1)
4.5.1
13/09/2021
Software License Manager <= 4.4.9 – Authenticated (Admin+) Stored Cross-Site Scripting
The Software License Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the License Key Prefix setting in versions up to, and including, 4.4.9 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.4.9
4.5.0
31/08/2021
Software License Manager <= 4.4.7 – Reflected Cross-Site Scripting
The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before outputting it back in the page in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
[*, 4.4.8)
4.4.8
11/08/2021
Software License Manager < 4.4.6 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
[*, 4.4.6)
4.4.6
08/07/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.