Extension WordPress
Vulnérabilités Under Construction Page (Pro)
Cette page rassemble les failles publiées pour Under Construction Page (Pro), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Under Construction Page (Pro)
4 fiches
UnderConstructionPage PRO <= 5.76 – Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and copying their…
*-5.76
5.81
10/07/2026
Under Construction <= 3.96 – Cross-Site Request Forgery via admin_action_ucp_dismiss_notice
The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the dismiss_notice function called via the admin_action_ucp_dismiss_notice action. This…
*-3.96
3.97
10/02/2023
Under Construction <= 3.96 – Cross-Site Request Forgery via admin_action_install_weglot
The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This…
*-3.96
3.97
10/02/2023
Under Construction <= 3.85 – Authenticated Stored Cross-Site Scripting
The Under Construction plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.85, that make it possible for attackers with administrative privileges to inject arbitrary web scripts via the social and connect icon…
*-3.85
3.86
20/01/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.