Extension WordPress
Vulnérabilités White Label CMS
Cette page rassemble les failles publiées pour White Label CMS, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de White Label CMS
8 fiches
White Label CMS <= 2.7.12 – Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings
The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.7.12
2.7.13
10/07/2026
White Label CMS <= 2.7.4 – Reflected Cross-Site Scripting
The White Label CMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-2.7.4
2.7.5
16/08/2024
White Label CMS <= 2.7.3 – Missing Authorization to Plugin Settings Reset
The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated…
*-2.7.3
2.7.4
09/05/2024
White Label CMS <= 2.4 – Authenticated (Administrator+) PHP Object Injection
The White Label CMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4 via deserialization of untrusted input in the legacy_import function. This allows administrator-level attackers to inject a PHP Object.…
*-2.4
2.5
08/12/2022
White Label MS <= 2.2.8 – Reflected Cross-Site Scripting
The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue
[*, 2.2.9)
2.2.9
07/02/2022
White Label CMS <= 1.5.2 – Cross-Site Request Forgery leading to Stored Cross-Site Scripting
The White Label CMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'wlcmsImport' function. This makes it possible for…
[*, 1.5.3)
1.5.3
29/04/2015
White Label CMS < 1.5.1 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, a related…
[*, 1.5.1)
1.5.1
21/10/2012
White Label CMS < 1.5.1 – Reflected Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in…
[*, 1.5.1)
1.5.1
21/10/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.