Extension WordPress
Vulnérabilités Testimonial – Testimonial Slider and Showcase Plugin
Cette page rassemble les failles publiées pour Testimonial – Testimonial Slider and Showcase Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Testimonial – Testimonial Slider and Showcase Plugin
2 fiches
Testimonial Slider <= 2.3.6 – Missing Authorization to Authenticated (Author+) Settings Update
The Testimonial Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tssSettingsUpdate() function in all versions up to, and including, 2.3.6. This makes it possible for authenticated attackers,…
*-2.3.6
2.3.7
05/03/2024
Testimonial Slider <= 2.2.6 – Stored Cross-Site Scripting
The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_title parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
*-2.2.6
2.2.7
05/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.