Extension WordPress
Vulnérabilités WP Cost Estimation & Payment Forms Builder
Cette page rassemble les failles publiées pour WP Cost Estimation & Payment Forms Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Cost Estimation & Payment Forms Builder
6 fiches
WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 – Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter
The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output…
*-10.5.97
10.6.1
08/07/2026
WP Cost Estimation & Payment Forms Builder <= 10.1.75 – Reflected Cross-Site Scripting
The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 10.1.75 due to insufficient input sanitization and output escaping. This makes it possible for…
*-10.1.75
10.1.76
15/04/2024
WP Cost Estimation & Payment Forms Builder <= 10.1.76 – Missing Authorization
The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 10.1.76. This makes it possible for…
*-10.1.76
10.1.77
15/04/2024
WP Cost Estimation & Payment Forms Builder <= 10.1.75 – Authenticated (Contributor+) SQL Injection
The WP Cost Estimation & Payment Forms Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.1.75 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-10.1.75
10.1.76
28/03/2024
WP Cost Estimation <= 9.642 – Missing Authorization to Arbitrary File Upload/Delete
The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_upload_form and lfb_removeFile AJAX actions in versions up to, and including, 9.642. This makes it…
[*, 9.644)
9.644
14/02/2019
WP Cost Estimation < 9.660 – Upload Directory Traversal
The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site.
[*, 9.660)
9.660
14/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.