Extension WordPress
Vulnérabilités underConstruction
Cette page rassemble les failles publiées pour underConstruction, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de underConstruction
5 fiches
underConstruction <= 1.21 – Authenticated (Administrator+) Stored Cross-Site Scripting
The underConstruction plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.21
1.22
29/03/2024
underConstruction <= 1.19 – Cross-Site Request Forgery to Construction Mode Disabled
The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
[*, 1.20)
1.20
26/05/2022
underConstruction <= 1.20 – Authenticated (Admin+) Stored Cross-Site Scripting
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability…
[*, 1.21)
1.21
26/05/2022
underConstruction <= 1.18 – Reflected Cross-Site Scripting
The underConstruction plugin
*-1.18
1.19
31/08/2021
underConstruction < 1.09 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.
[*, 1.09)
1.09
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.