Extension WordPress
Vulnérabilités WHMpress – WHMCS WordPress Integration Plugin
Cette page rassemble les failles publiées pour WHMpress – WHMCS WordPress Integration Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WHMpress – WHMCS WordPress Integration Plugin
5 fiches
WHMpress <= 6.2-revision-9 – Authenticated (Contributor+) Local File Inclusion
The WHMpress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.2-revision-9. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
* – 6.2-revision-9
Non indiqué
16/05/2025
WHMpress <= 6.2-revision-9 – Unauthenticated Local File Inclusion
The WHMpress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.2-revision-9. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
* – 6.2-revision-9
Non indiqué
16/05/2025
WHMpress <= 6.3-revision-0 – Unauthenticated Local File Inclusion to Arbitrary Options Update
The WHMpress – WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_domain_search_ajax_extended_results() function. This makes it possible for unauthenticated attackers to include and…
* – 6.3-revision-0
6.3-revision-1
27/02/2025
WHMpress <= 6.2-revision-5 – Missing Authorization to Authenticated (Subscriber+) Settings Update
The WHMpress – WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.2-revision-5. This makes it possible for authenticated…
* – 6.2-revision-5
Non indiqué
12/08/2024
WHMpress <= 6.2-revision-5 – Reflected Cross-Site Scripting
The WHMpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2-revision-5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
* – 6.2-revision-5
Non indiqué
12/08/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.