Extension WordPress

Vulnérabilités Tumult Hype Animations

Cette page rassemble les failles publiées pour Tumult Hype Animations, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
1Critiques
4Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Tumult Hype Animations

4 fiches

CVE-2024-11082 Critique · 9,9
Tumult Hype Animations

Tumult Hype Animations <= 1.9.15 – Authenticated (Author+) Arbitrary File Upload via hypeanimations_panel Function

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers,…

Versions affectées

*-1.9.15

Correctif

1.9.16

Publication

27/11/2024

CVE-2024-30461 Moyenne · 6,1
Tumult Hype Animations

Tumult Hype Animations <= 1.9.11 – Cross-Site Request Forgery to Cross-Site Scripting

The Tumult Hype Animations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.11. This is due to missing or incorrect nonce validation on the hypeanimations_updatecontainer() function. This makes it possible…

Versions affectées

*-1.9.11

Correctif

1.9.12

Publication

28/03/2024

CVE-2024-2890 Élevée · 8,8
Tumult Hype Animations

Tumult Hype Animations <= 1.9.12 – Authenticated (Author+) Arbitrary File Upload

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the hypeanimations_panel_upload() functionin all versions up to, and including, 1.9.12. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.9.12

Correctif

1.9.13

Publication

26/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités