Extension WordPress
Vulnérabilités Themify – WooCommerce Product Filter
Cette page rassemble les failles publiées pour Themify – WooCommerce Product Filter, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Themify – WooCommerce Product Filter
6 fiches
Themify – WooCommerce Product Filter <= 1.5.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.5.1
1.5.2
23/09/2024
Themify – WooCommerce Product Filter <= 1.4.9 – Unauthenticated SQL Injection via conditions Parameter
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack…
*-1.4.9
1.5.0
20/06/2024
Themify – WooCommerce Product Filter <= 1.4.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.4.3
1.4.4
11/03/2024
Themify – WooCommerce Product Filter <= 1.4.3 – Cross-Site Request Forgery
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.3. This is due to missing or incorrect nonce validation on the wpf_search page. This makes…
*-1.4.3
1.4.4
11/03/2024
Themify – WooCommerce Product Filter <= 1.4.3 – Reflected Cross-Site Scripting
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.4.3
1.4.4
11/03/2024
Themify – WooCommerce Product Filter <= 1.3.7 – Reflected Cross-Site Scripting
Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
*-1.3.7
1.3.8
18/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.