Extension WordPress

Vulnérabilités Starfish Review Generation & Marketing for WordPress

Cette page rassemble les failles publiées pour Starfish Review Generation & Marketing for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Starfish Review Generation & Marketing for WordPress

5 fiches

CVE-2025-15157 Élevée · 8,8
Starfish Review Generation & Marketing for WordPress

Starfish Review Generation & Marketing for WordPress <= 3.1.19 – Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up…

Versions affectées

*-3.1.19

Correctif

3.1.20

Publication

13/02/2026

CVE-2025-39533 Élevée · 8,8
Starfish Review Generation & Marketing for WordPress

Starfish Review Generation & Marketing <= 3.1.19 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'starfish-execute-restore-default-options' AJAX action in all versions…

Versions affectées

*-3.1.19

Correctif

3.1.20

Publication

16/04/2025

CVE-2023-33999 Moyenne · 6,1
Starfish Review Generation & Marketing for WordPress

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

2.1.0-3.0.36

Correctif

3.1.0

Publication

18/07/2023

CVE-2022-4974 Moyenne · 6,3
Starfish Review Generation & Marketing for WordPress

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 3.0.26)

Correctif

3.0.26

Publication

04/03/2022

Vulnérabilité Élevée · 8,8
Starfish Review Generation & Marketing for WordPress

Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

[*, 2.0.1)

Correctif

2.0.1

Publication

25/02/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités