Extension WordPress
Vulnérabilités Starfish Review Generation & Marketing for WordPress
Cette page rassemble les failles publiées pour Starfish Review Generation & Marketing for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Starfish Review Generation & Marketing for WordPress
5 fiches
Starfish Review Generation & Marketing for WordPress <= 3.1.19 – Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults
The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up…
*-3.1.19
3.1.20
13/02/2026
Starfish Review Generation & Marketing <= 3.1.19 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'starfish-execute-restore-default-options' AJAX action in all versions…
*-3.1.19
3.1.20
16/04/2025
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
2.1.0-3.0.36
3.1.0
18/07/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 3.0.26)
3.0.26
04/03/2022
Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…
[*, 2.0.1)
2.0.1
25/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.