Extension WordPress
Vulnérabilités Ultimate FAQ Accordion Plugin
Cette page rassemble les failles publiées pour Ultimate FAQ Accordion Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ultimate FAQ Accordion Plugin
7 fiches
Ultimate FAQ Accordion Plugin <= 2.4.7 – Authenticated (Author+) Stored Cross-Site Scripting via FAQ Content
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the…
*-2.4.7
2.4.8
08/04/2026
Ultimate FAQ <= 2.4.3 – Cross-Site Request Forgery
The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-2.4.3
2.4.4
08/11/2025
Ultimate FAQ <= 2.1.1 – Missing Authorization to Arbitrary FAQ Creation
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber…
[*, 2.1.2)
2.1.2
27/12/2021
Ultimate FAQ <= 1.8.29 – Reflected Cross-Site Scripting
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
*-1.8.29
1.8.30
06/01/2020
Ultimate FAQ <= 1.8.24 – Unauthenticated Options Import/Export
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
[*, 1.8.25)
1.8.25
20/09/2019
Ultimate FAQ <= 1.8.24 – Cross-Site Scripting
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
[*, 1.8.25)
1.8.25
20/09/2019
Ultimate Faqs <= 1.8.21 – Cross-Site Scripting
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
[*, 1.8.22)
1.8.22
08/05/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.