Extension WordPress
Vulnérabilités Verge3D Publishing and E-Commerce
Cette page rassemble les failles publiées pour Verge3D Publishing and E-Commerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Verge3D Publishing and E-Commerce
6 fiches
Verge3D <= 4.9.4 – Missing Authorization
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.4. This makes it possible for unauthenticated attackers to…
*-4.9.4
4.9.5
05/06/2025
Verge3D <= 4.9.3 – Reflected Cross-Site Scripting
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-4.9.3
4.9.4
29/05/2025
Verge3D <= 4.9.0 – Cross-Site Request Forgery
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.0. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-4.9.0
4.9.3
17/04/2025
Verge3D <= 4.8.2 – Cross-Site Request Forgery
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on a function. This makes it possible…
*-4.8.2
4.8.3
27/03/2025
Verge3D <= 4.8.0 – Reflected Cross-Site Scripting
The Verge3D plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-4.8.0
4.8.1
15/01/2025
Verge3D <= 4.5.2 – Authenticated(Subscriber+) Arbitrary File Upload
The Verge3D Publishing and E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'v3d_upload_app_file' function in all versions up to, and including, 4.5.2. This makes it possible for authenticated…
*-4.5.2
4.5.3
27/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.