Extension WordPress
Vulnérabilités Clone
Cette page rassemble les failles publiées pour Clone, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Clone
8 fiches
Clone <= 2.4.6 – Unauthenticated PHP Object Injection via 'recursive_unserialized_replace'
The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a…
*-2.4.6
2.4.7
19/11/2024
Clone <= 2.4.5 – Missing Authorization
The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpa_wpc_ajax_install_new() function in versions up to, and including, 2.4.5. This makes it possible for authenticated attackers, with subscriber-level…
*-2.4.5
2.4.6
16/08/2024
Inisev Analyst Module <= Various Versions – Missing Authorization
Multiple plugins and/or themes by Inisev for WordPress are vulnerable to unauthorized access due to a missing capability check on several functions in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
*-2.4.3
2.4.4
10/04/2024
WP Clone <= 2.4.2 – Sensitive Information Exposure
The Clone plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to download database backups made with the plugin resulting in the potential…
*-2.4.2
2.4.3
18/12/2023
Inisev Plugins (Various Versions) – Missing Authorization on handle_installation function
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible…
*-2.3.7
2.3.8
27/07/2023
Inisev Plugins (Various Versions) – Cross-Site Request Forgery on handle_installation function
Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions.…
*-2.3.7
2.3.8
27/07/2023
Clone <= 2.3.7 – Missing Authorization via wp_ajax_tifm_save_decision
The Clone plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_tifm_save_decision function in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers with subscriber-level…
*-2.3.7
2.3.8
08/03/2023
Clone <= 2.3.7 – Cross-Site Request Forgery via wp_ajax_tifm_save_decision
The Clone plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.7. This is due to missing or incorrect nonce validation on the wp_ajax_tifm_save_decision function. This makes it possible for unauthenticated attackers…
*-2.3.7
2.3.8
08/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.