Extension WordPress
Vulnérabilités Post Grid Gutenberg Blocks – PostX, page 2
Cette page rassemble les failles publiées pour Post Grid Gutenberg Blocks – PostX, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Post Grid Gutenberg Blocks – PostX
25 fiches
PostX – Gutenberg Blocks for Post Grid <= 2.9.9 – Unauthenticated Cross-Site Scripting
The PostX – Gutenberg Blocks for Post Grid plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-2.9.9
2.9.10
23/06/2023
PostX Gutenberg Blocks Saved Templates Addon <= 2.4.9 – Private Content Disclosure
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read,…
*-2.4.9
2.4.10
26/08/2021
PostX – Gutenberg Blocks for Post Grid <= 2.4.9 – Stored Cross-Site Scripting
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's shortcode.
[*, 2.4.10)
2.4.10
26/08/2021
PostX – Gutenberg Blocks for Post Grid <= 2.4.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block.
[*, 2.4.10)
2.4.10
26/08/2021
PostX – Gutenberg Blocks for Post Grid <= 2.4.9 – Unauthorized Access Controls
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify, delete or add ultp_options values.
[*, 2.4.10)
2.4.10
17/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.