Extension WordPress
Vulnérabilités wpCentral
Cette page rassemble les failles publiées pour wpCentral, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de wpCentral
3 fiches
wpCentral <= 1.5.7 – Cross-Site Request Forgery
The wpCentral plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the wpcentral_page_handler() function. This makes it possible for unauthenticated attackers…
*-1.5.7
Non indiqué
05/09/2023
wpCentral <= 1.5.0 – Improper Access Control to Privilege Escalation
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key which makes it possible for an unauthenticated user to log-in to a vulnerable site as an administrator.
*-1.5.0
1.5.1
17/02/2020
wpCentral <= 1.4.7 – Privilege Escalation
The wpCentral for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.4.7 due to missing authorization checks and validation on the wpc_fetch_authkey() and my_wpc_signon() functions. This makes it possible for authenticated users, with low-level…
[*, 1.4.8)
1.4.8
24/01/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.