Extension WordPress
Vulnérabilités WebberZone Top 10 , Popular Posts
Cette page rassemble les failles publiées pour WebberZone Top 10 , Popular Posts, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WebberZone Top 10 , Popular Posts
10 fiches
Top 10 <= 4.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Top 10 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-4.1.0
4.1.1
07/05/2025
Top 10 <= 3.3.2 – Cross-Site Request Forgery via edit_count_ajax
The Top 10 – WordPress Popular posts by WebberZone plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation on the 'edit_count_ajax'…
*-3.3.2
3.3.3
03/11/2023
Top 10 – Popular posts plugin – <= 3.2.4 – Authenticated(Admin+) Stored Cross-Site Scripting
The Top 10 – Popular posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.2.4
3.2.5
22/02/2023
Top 10 – Popular posts plugin for WordPress <= 3.2.4 – Missing Authorization on tptn_chart_data
The Top 10 – Popular posts plugin for WordPress is vulnerable to insufficient access control in the 'tptn_chart_data' AJAX action in versions up to, and including, 3.2.4. This allows authenticated attackers to access chart data granted they can…
*-3.2.4
3.2.5
22/02/2023
Top 10 – Popular posts plugin for WordPress <= 3.2.3 – Cross-Site Request Forgery via tptn_ajax_clearcache
The Top 10 – Popular posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.3. This is due to missing or incorrect nonce validation on the tptn_ajax_clearcache function. This makes it…
*-3.2.3
3.2.4
20/02/2023
Top 10 – Popular posts plugin for WordPress <= 3.2.3 – Missing Authorization on tptn_ajax_clearcache
The Top 10 – Popular posts plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability check on the tptn_ajax_clearcache function in versions up to, and including, 3.2.3. This makes it possible for authenticated…
*-3.2.3
3.2.4
20/02/2023
Top 10 – Popular posts plugin for WordPress <= 3.2.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Blocks
The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping on…
*-3.2.2
3.2.3
29/12/2022
Top 10 <= 2.9.4 – Cross-Site Request Forgery Bypass
The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the tptn_export_tables() function. This makes it possible for unauthenticated…
[*, 2.9.5)
2.9.5
16/09/2020
Top 10 – Popular posts plugin for WordPress <= 2.4.3 – SQL Injection
The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘get_results’ parameter in versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter…
[*, 2.4.4)
2.4.4
13/12/2017
Top 10 – Popular posts plugin for WordPress < 2.3.1 – Cross-Site Scripting
The Top 10 – Popular posts plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for…
[*, 2.3.1)
2.3.1
15/07/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.