Extension WordPress
Vulnérabilités WP Custom Admin Interface
Cette page rassemble les failles publiées pour WP Custom Admin Interface, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Custom Admin Interface
7 fiches
WP Custom Admin Interface <= 7.42 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The WP Custom Admin Interface plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level…
*-7.42
7.43
20/03/2026
Custom Admin Interface <= 7.41 – Missing Authorization
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.41. This makes it possible for authenticated attackers, with…
*-7.41
7.42
25/01/2026
Custom Admin Interface <= 7.40 – Missing Authorization
The Custom Admin Interface plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.40. This makes it possible for authenticated attackers, with subscriber-level access…
*-7.40
7.41
31/12/2025
WP Custom Admin Interface <= 7.31 – Missing Authorization via wpcai_pro_notice_disable
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the wpcai_pro_notice_disable function in versions up to, and including, 7.31. This makes it possible for authenticated…
*-7.31
7.32
13/11/2023
WP Custom Admin Interface <= 7.32 – Cross-Site Request Forgery to Transients Deletion
The WP Custom Admin Interface plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.32. This is due to missing or incorrect nonce validation on the wp_custom_admin_interface_delete_transients function. This makes it possible…
[*, 7.33)
7.33
29/09/2023
WP Custom Admin Interface <= 7.32 – Missing Authorization to Transients Deletion
The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_custom_admin_interface_delete_transients function in versions up to, and including, 7.32. This makes it possible for authenticated…
[*, 7.33)
7.33
29/09/2023
WP Custom Admin Interface <= 7.28 – Authenticated (Administrator+) PHP Object Injection
The WP Custom Admin Interface plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.28, via deserialization of untrusted input in the northernbeacheswebsites_information and wp_custom_admin_interface_import_settings functions. This allows administrator-level attackers to inject…
*-7.28
7.29
13/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.