Extension WordPress

Vulnérabilités Product Carousel Slider & Grid Ultimate for WooCommerce

Cette page rassemble les failles publiées pour Product Carousel Slider & Grid Ultimate for WooCommerce, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Product Carousel Slider & Grid Ultimate for WooCommerce

7 fiches

CVE-2025-24681 Moyenne · 4,4
Product Carousel Slider & Grid Ultimate for WooCommerce

Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.10.0 – Authenticated (Editor+) Stored Cross-Site Scripting

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.10.0

Correctif

1.10.1

Publication

24/01/2025

CVE-2024-12040 Élevée · 8,8
Product Carousel Slider & Grid Ultimate for WooCommerce

Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.10 – Authenticated (Contributor+) Local File Inclusion via 'theme'

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.10 via the 'theme' attribute of the `wcpcsu` shortcode. This makes it possible…

Versions affectées

*-1.9.10

Correctif

1.10.0

Publication

11/12/2024

CVE-2024-44048 Élevée · 8,8
Product Carousel Slider & Grid Ultimate for WooCommerce

Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.10 – Authenticated (Contributor+) Local File Inclusion

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.10. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-1.9.10

Correctif

1.10.0

Publication

16/09/2024

CVE-2024-1950 Élevée · 7,5
Product Carousel Slider & Grid Ultimate for WooCommerce

Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.7 – Authenticated(Contributor+) PHP Object Injection

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input via shortcode. This makes it possible for…

Versions affectées

*-1.9.7

Correctif

1.9.8

Publication

05/03/2024

Vulnérabilité Moyenne · 6,4
Product Carousel Slider & Grid Ultimate for WooCommerce

WooCommerce Product Carousel, Slider & Grid Ultimate <= 1.8.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The WooCommerce Product Carousel, Slider & Grid Ultimate plugin for WordPress, versions up to and including 1.8.6, is vulnerable to Cross-Site Scripting. The script /includes/carousel.php (as well as other setting-related scripts) does not sanitize user input. This allows…

Versions affectées

*-1.8.6

Correctif

1.8.7

Publication

05/08/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités