Extension WordPress

Vulnérabilités WP Custom Admin Interface

Cette page rassemble les failles publiées pour WP Custom Admin Interface, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Custom Admin Interface

7 fiches

CVE-2026-32521 Moyenne · 6,4
WP Custom Admin Interface

WP Custom Admin Interface <= 7.42 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The WP Custom Admin Interface plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-7.42

Correctif

7.43

Publication

20/03/2026

CVE-2023-47763 Informationnelle
WP Custom Admin Interface

WP Custom Admin Interface <= 7.31 – Missing Authorization via wpcai_pro_notice_disable

The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized admin notice dismissal due to a missing capability check on the wpcai_pro_notice_disable function in versions up to, and including, 7.31. This makes it possible for authenticated…

Versions affectées

*-7.31

Correctif

7.32

Publication

13/11/2023

Vulnérabilité Moyenne · 4,3
WP Custom Admin Interface

WP Custom Admin Interface <= 7.32 – Cross-Site Request Forgery to Transients Deletion

The WP Custom Admin Interface plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.32. This is due to missing or incorrect nonce validation on the wp_custom_admin_interface_delete_transients function. This makes it possible…

Versions affectées

[*, 7.33)

Correctif

7.33

Publication

29/09/2023

CVE-2023-44988 Moyenne · 4,3
WP Custom Admin Interface

WP Custom Admin Interface <= 7.32 – Missing Authorization to Transients Deletion

The WP Custom Admin Interface plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_custom_admin_interface_delete_transients function in versions up to, and including, 7.32. This makes it possible for authenticated…

Versions affectées

[*, 7.33)

Correctif

7.33

Publication

29/09/2023

CVE-2022-4043 Élevée · 7,2
WP Custom Admin Interface

WP Custom Admin Interface <= 7.28 – Authenticated (Administrator+) PHP Object Injection

The WP Custom Admin Interface plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.28, via deserialization of untrusted input in the northernbeacheswebsites_information and wp_custom_admin_interface_import_settings functions. This allows administrator-level attackers to inject…

Versions affectées

*-7.28

Correctif

7.29

Publication

13/12/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités