Extension WordPress
Vulnérabilités Testimonial – WordPress Testimonial Showcase Plugin Grid Plus Testimonial Slider
Cette page rassemble les failles publiées pour Testimonial – WordPress Testimonial Showcase Plugin Grid Plus Testimonial Slider, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Testimonial – WordPress Testimonial Showcase Plugin Grid Plus Testimonial Slider
2 fiches
Testimonial Builder <= 1.6.1 – Authenticated Stored Cross-Site Scripting
The Testimonial Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blockip’ parameter in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.6.1
1.6.2
07/11/2021
Testimonial < 1.6.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed.
[*, 1.6.0)
1.6.0
13/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.