Extension WordPress
Vulnérabilités Wordfence Security – Firewall, Malware Scan, and Login Security
Cette page rassemble les failles publiées pour Wordfence Security – Firewall, Malware Scan, and Login Security, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Wordfence Security – Firewall, Malware Scan, and Login Security
12 fiches
Wordfence Security – Firewall & Malware Scan <= 7.6.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored…
*-7.6.0
7.6.1
06/09/2022
Wordfence Security – Firewall & Malware Scan <= 7.1.13 – Reflected Cross-Site Scripting and Information Disclosure
Wordfence before 7.1.14 was vulnerable in certain unusual configurations to Reflected Cross-Site Scripting, as well as full path disclosure and author name disclosure.
[*, 7.1.14)
7.1.14
02/10/2018
Wordfence Security – Firewall & Malware Scan 6.1.1 – 6.1.6 – Reflected Cross-Site Scripting
The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adminURL’ parameter in versions 6.1.1 through 6.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
6.1.1-6.1.6
6.1.7
10/05/2016
Wordfence <= 5.1.4 – Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.
[*, 5.1.5)
5.1.5
08/12/2014
Wordfence Security <= 5.2.3 – Stored Cross-Site Scripting via HTTP_HOST
The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['HTTP_HOST']' in PHP in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized…
*-5.2.3
5.2.4
27/09/2014
Wordfence <= 5.2.3 – Stored Cross-Site Scripting via REQUEST_URI
The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['REQUEST_URI']' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-5.2.3
5.2.4
14/09/2014
Wordfence <= 5.2.3 – Multiple Protection Mechanism Bypasses
The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. These allow unauthenticated attackers to bypass exploit protection and throttling restrictions.
[*, 5.2.4)
5.2.4
14/09/2014
Wordfence <= 5.2.2 – Stored Cross-Site Scripting
The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer Header in versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 5.2.3)
5.2.3
08/09/2014
Wordfence Security <= 3.8.1 – Stored Cross-Site Scripting
The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wfwhois’ parameter in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.8.1
3.8.3
01/08/2014
Wordfence Security – Firewall & Malware Scan <= 5.1.3 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin/admin.php.
*-5.1.3
5.1.4
30/07/2014
Wordfence < 3.3.7 – Reflected Cross-Site Scripting
The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘email’ parameter in versions before 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
[*, 3.3.7)
3.3.7
19/10/2012
Wordfence Security – Firewall & Malware Scan <= 3.3.6 – Stored Cross-Site Scripting
WordPress plugin Wordfence versions 3.3.6 and older were vulnerable to Cross-Site Scripting via the unlockEmail functionality.
*-3.3.6
3.3.7
19/10/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.