Extension WordPress
Vulnérabilités LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
Cette page rassemble les failles publiées pour LightStart – Maintenance Mode, Coming Soon and Landing Page Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
7 fiches
ThemeIsle SDK <= Various Versions – Missing Authorization
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…
*-2.6.9
2.6.10
01/02/2024
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 – Missing Authorization
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including,…
*-2.6.8
2.6.9
05/01/2024
WP Maintenance Mode & Coming Soon <= 2.4.4 – Cross-Site Request Forgery
The WP Maintenance Mode & Coming Soon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.4. This is due to missing nonce validation on the reset_plugin_settings, subscribers_empty_list, dismiss_notices, subscribers_export, add_subscriber, &…
*-2.4.4
2.4.5
20/06/2022
WP Maintenance Mode <= 2.0.6 – Remote Code Execution
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.
[*, 2.0.7)
2.0.7
14/12/2018
WP Maintenance Mode <= 2.0.6 – Authenticated Information Disclosure
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
[*, 2.0.7)
2.0.7
06/07/2016
WP Maintenance Mode <= 2.0.6 – Missing Authorization
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.
[*, 2.0.7)
2.0.7
06/07/2016
WP Maintenance Mode <= 1.8.7 – Missing Authorization Checks & Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
[*, 1.8.8)
1.8.8
05/06/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.