Extension WordPress
Vulnérabilités WP Custom Cursors | WordPress Cursor Plugin
Cette page rassemble les failles publiées pour WP Custom Cursors | WordPress Cursor Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Custom Cursors | WordPress Cursor Plugin
6 fiches
WP Custom Cursors | WordPress Cursor <= 3.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes…
*-3.2
Non indiqué
07/10/2023
WP Custom Cursors <= 3.1 – Authenticated (Admin+) SQL Injection
The WP Custom Cursors | WordPress Cursor Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_row' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and…
*-3.1
3.2
24/05/2023
WP Custom Cursors < 3.2 – Cross-Site Request Forgery
The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers…
[*, 3.2)
3.2
15/05/2023
WP Custom Cursors <= 3.0.1 – Authenticated (Administrator+) SQL Injection
The WP Custom Cursors plugin for WordPress is vulnerable to SQL Injection via the ‘edit_row’ parameter and potentially others in versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of…
*-3.0.2
3.0.3
21/09/2022
WP Custom Cursors <= 3.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Custom Cursors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_text’ parameter as well as others in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes…
*-3.0
3.0.1
21/09/2022
WP Custom Cursors <= 3.0 – Cross-Site Request Forgery to Cursor Manipulation
The WP Custom Cursors plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0. This is due to missing or incorrect nonce validation in the ~/wp-custom-cursors-add-new.php file. This makes it possible for…
*-3.0
3.0.1
21/09/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.