Extension WordPress
Vulnérabilités SpeedyCache – Cache, Optimization, Performance
Cette page rassemble les failles publiées pour SpeedyCache – Cache, Optimization, Performance, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SpeedyCache – Cache, Optimization, Performance
4 fiches
SpeedyCache <= 1.1.8 – Cross-Site Request Forgery
The SpeedyCache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.8. This is due to missing or incorrect nonce validation on the speedycache_options_page_request() function. This makes it possible for unauthenticated attackers…
*-1.1.8
1.1.9
16/08/2024
SpeedyCache <= 1.1.3 – Missing Authorization to Plugin Options Update
The SpeedyCache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_save_varniship, speedycache_img_update_settings, speedycache_preloading_add_settings, and speedycache_preloading_delete_resource functions in all versions up to, and including, 1.1.3. This makes it possible…
*-1.1.3
1.1.4
16/12/2023
SpeedyCache <= 1.1.2 – Authenticated (Subscriber+) Server-Side Request Forgery
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.2 via the speedycache_create_test_cache() function. This makes it possible for authenticated attackers, subscriber-level access and above,…
*-1.1.2
1.1.3
04/12/2023
SpeedyCache <= 1.1.2 – Missing Authorization via speedycache_create_test_cache
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the speedycache_create_test_cache function in all versions up to, and including, 1.1.2. This makes it possible…
*-1.1.2
1.1.3
01/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.