Extension WordPress
Vulnérabilités WP Coder – Insert & Manage Code Snippets
Cette page rassemble les failles publiées pour WP Coder – Insert & Manage Code Snippets, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Coder – Insert & Manage Code Snippets
6 fiches
WP Coder – Code Snippets + HTML, CSS, JS and PHP Injection <= 3.6.0 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The WP Coder – Code Snippets + HTML, CSS, JS and PHP Injection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6. This is due to missing or incorrect nonce…
*-3.6
3.6.1
31/01/2025
WP Coder <= 3.5 – Authenticated (Editor+) Stored Cross-Site Scripting
The WP Coder – Powerful HTML, CSS, JS and PHP Injection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.5 due to insufficient input sanitization and output escaping.…
*-3.5
3.5.1
18/03/2024
Multiple Wow-Company Plugins (Various Versions) — Reflected Cross-Site Scripting via 'page' parameter
Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-2.5.5
2.5.6
22/05/2023
WP Coder – add custom html, css and js code <= 2.5.3 – Authenticated (Admin+) SQL Injection
The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user…
*-2.5.3
2.5.4
17/02/2023
WP Coder <= 2.5.2 – Cross-Site Request Forgery
The WP Coder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation in the ~/admin/partials/tools-data-base.php file. This makes it possible for unauthenticated…
*-2.5.2
2.5.3
26/07/2022
WP Coder <= 2.5.1 – Remote File Inclusion leading to Remote Code Execution via Cross-Site Request Forgery
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
*-2.5.1
2.5.2
05/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.