Extension WordPress

Vulnérabilités Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Cette page rassemble les failles publiées pour Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
4Critiques
10Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

12 fiches

CVE-2022-0769 Critique · 9,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 – Unauthenticated SQL Injection

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and…

Versions affectées

*-3.1.0

Correctif

Non indiqué

Publication

13/04/2022

CVE-2015-9395 Élevée · 8,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership Plugin <= 1.5.63 – Authenticated Blind SQL Injection

The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via ajax actions, by exploiting following WP ajax actions SQL injections attacks can be performed: `edit_video`, `delete_photo`, `delete_gallery`, `delete_video`, `reload_photos`, `edit_gallery`, `edit_gallery_confirm`, `edit_photo`, `edit_photo_confirm`, `edit_video_confirm`, `set_as_main_photo`, `sort_photo_list`,`sort_gallery_list`, `reload_videos`…

Versions affectées

[*, 1.5.64)

Correctif

1.5.64

Publication

01/12/2015

CVE-2015-4109 Critique · 9,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra <= 1.5.15 – Multiple SQL Injection

Multiple SQL injection vulnerabilities in the ratings module in the Users Ultra plugin before 1.5.16 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) data_target or (2) data_vote parameter in a rating_vote (wp_ajax_nopriv_rating_vote) action…

Versions affectées

*-1.5.15

Correctif

1.5.16

Publication

04/06/2015

Vulnérabilité Élevée · 7,2
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.4.95 – SQL Injection

The "Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin" plugin for WordPress is vulnerable to SQL Injection via the ‘$gal_id’ parameter in versions up to, and including, 1.4.95 due to insufficient escaping on the…

Versions affectées

*-1.4.95

Correctif

1.4.96

Publication

17/04/2015

Vulnérabilité Élevée · 8,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin < 1.4.36 – SQL Injection

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin for WordPress is vulnerable to generic SQL Injection via the ‘cate_id’ parameter in versions up to, and including, 1.4.35 due to insufficient escaping on the…

Versions affectées

[*, 1.4.36)

Correctif

1.4.36

Publication

09/02/2015

Vulnérabilité Critique · 9,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.3.58 – SQL Injection

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.58 due to insufficient escaping on the user-supplied $id parameter and…

Versions affectées

*-1.3.58

Correctif

1.3.59

Publication

22/10/2014

Vulnérabilité Critique · 9,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 1.3.58 – SQL Injection

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.58 due to insufficient escaping on the user-supplied $id parameter and…

Versions affectées

*-1.3.58

Correctif

1.3.59

Publication

22/10/2014

Vulnérabilité Élevée · 8,8
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin

Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin <= 3.1.0 – SQL Injection

The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.0 due to insufficient escaping on the user-supplied parameter and lack…

Versions affectées

*-3.1.0

Correctif

Non indiqué

Publication

29/09/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités