Extension WordPress
Vulnérabilités WDSocialWidgets
Cette page rassemble les failles publiées pour WDSocialWidgets, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WDSocialWidgets
5 fiches
Spider Facebook <= 1.0.15 – Cross-Site Request Forgery
The Spider Facebook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.15. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized…
*-1.0.15
Non indiqué
25/10/2023
Spider Facebook <= 1.0.15 – Reflected Cross-Site Scripting
The WDSocialWidgets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.0.15
Non indiqué
17/10/2023
WordPress Facebook <= 1.0.13 – SQL Injection
The WordPress Facebook plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in versions up to, and including, 1.0.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-1.0.13
1.0.14
02/05/2017
WDSocialWidgets < 1.0.11 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the appid parameter in a registration task to the default URI or…
[*, 1.0.11)
1.0.11
26/01/2015
Spider Facebook <= 1.0.8 – SQL Injection
The Spider Facebook plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in versions up to, and including, 1.0.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the…
*-1.0.8
1.0.9
07/09/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.