Extension WordPress
Vulnérabilités WP EXtra – One Click Optimize
Cette page rassemble les failles publiées pour WP EXtra – One Click Optimize, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP EXtra – One Click Optimize
4 fiches
WP EXtra <= 6.4 – Cross-Site Request Forgery ToolImport
The WP EXtra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4. This is due to missing or incorrect nonce validation on the ToolImport function. This makes it possible for unauthenticated…
*-6.4
6.5
16/11/2023
WP EXtra <= 6.2 – Missing Authorization to Arbitrary Email Sending
The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it…
*-6.2
6.3
25/10/2023
WP EXtra <= 6.2 – Missing Authorization to .htaccess File Modification
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with…
*-6.2
6.3
24/10/2023
WP EXtra <= 6.2 – Missing Authorization to Export Settings
The WP EXtra plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with…
*-6.2
6.3
19/10/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.