Extension WordPress

Vulnérabilités Starbox – the Author Box for Humans

Cette page rassemble les failles publiées pour Starbox – the Author Box for Humans, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Starbox – the Author Box for Humans

6 fiches

CVE-2024-8239 Moyenne · 6,4
Starbox – the Author Box for Humans

Starbox <= 3.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter URL Field

The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter URL field in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping.…

Versions affectées

*-3.5.2

Correctif

3.5.3

Publication

09/09/2024

CVE-2024-7955 Moyenne · 4,4
Starbox – the Author Box for Humans

Starbox – the Author Box for Humans <= 3.5.1 – Authenticated (Admin+) Stored Cross-Site Scripting

The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.5.1

Correctif

3.5.2

Publication

20/08/2024

CVE-2023-6806 Moyenne · 6,4
Starbox – the Author Box for Humans

Starbox <= 3.4.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-3.4.8

Correctif

3.5.0

Publication

06/02/2024

CVE-2024-0256 Moyenne · 6,4
Starbox – the Author Box for Humans

Starbox <= 3.4.8 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Display Name and Social Settings

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-3.4.8

Correctif

3.5.0

Publication

31/01/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités