Extension WordPress
Vulnérabilités WP Go Maps – Google Map, OpenStreetMap, Leaflet Map, page 2
Cette page rassemble les failles publiées pour WP Go Maps – Google Map, OpenStreetMap, Leaflet Map, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
25 fiches
WP Google Maps <= 7.11.34 – Cross-Site Request Forgery to Cross-Site Scripting
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
[*, 7.11.35)
7.11.35
08/07/2019
WP Google Maps <= 7.11.27 – Cross-Site Request Forgery
The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.27. This is due to missing nonce validation on the wpgmza_settings_page_post() function. This makes it possible for authenticated attackers…
[*, 7.11.28)
7.11.28
03/06/2019
WP Google Maps < 7.10.43 – Reflected Cross-Site Scripting
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
*-7.10.41
7.10.43
05/02/2019
WP Google Maps <= 6.3.14 – Stored Cross-Site Scripting
The WP Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_store_locator_query_string’ parameter in versions up to, and including, 6.3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-6.3.14
6.3.15
10/11/2016
WP Google Maps <= 6.0.26 – Reflected Cross-Site Scripting
The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.26 via the 'poly_id' parameter (in the edit_poly, edit_polyline, or edit_marker actions) due to insufficient input sanitization and output escaping.…
[*, 6.0.27)
6.0.27
15/10/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.