Extension WordPress
Vulnérabilités External Links – nofollow, noopener & new window
Cette page rassemble les failles publiées pour External Links – nofollow, noopener & new window, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de External Links – nofollow, noopener & new window
3 fiches
External Links <= 2.57 – Cross-Site Request Forgery via action_admin_action_wpel_dismiss_notice
The External Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.7. This is due to missing or incorrect nonce validation on the 'action_admin_action_wpel_dismiss_notice' function. This makes it possible for unauthenticated…
*-2.57
2.58
08/03/2023
External Links <= 2.55 – Authenticated (Administrator+) Cross-Site Scripting
The External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.55 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
*-2.55
2.56
20/11/2022
WP External Links < 1.81 – Authenticated Stored Cross-Site Scripting
The WP External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary…
[*, 1.81)
1.81
23/03/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.