Extension WordPress
Vulnérabilités Subscribe To Comments Reloaded
Cette page rassemble les failles publiées pour Subscribe To Comments Reloaded, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Subscribe To Comments Reloaded
5 fiches
Subscribe To Comments Reloaded <= 240119 – Improper Authorization to Unauthenticated Arbitrary Subscription Management
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This…
*-240119
Non indiqué
04/05/2026
Subscribe To Comments Reloaded <= 220725 – Unauthenticated Sensitive Information Exposure
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 220725 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log…
*-220725
240119
05/04/2024
Subscribe To Comments Reloaded <= 211130 – Cross-Site Request Forgery
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin mass update settings, manage subscriptions > add a new subscription, update subscription, delete Subscription.
*-211130
220502
29/04/2022
Subscribe To Comments Reloaded < 150820 – Reflected Cross-Site Scripting
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘srp’ parameter in versions up to, and including, 150611 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 150820)
150820
20/08/2015
Subscribe To Comments Reloaded <= 140129 – Cross-Site Request Forgery to Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the…
*-140129
140219
18/02/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.