Extension WordPress

Vulnérabilités LightStart – Maintenance Mode, Coming Soon and Landing Page Builder

Cette page rassemble les failles publiées pour LightStart – Maintenance Mode, Coming Soon and Landing Page Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
1Critiques
7Avec correctif
9,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de LightStart – Maintenance Mode, Coming Soon and Landing Page Builder

7 fiches

CVE-2024-1047 Moyenne · 5,3
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder

ThemeIsle SDK <= Various Versions – Missing Authorization

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.6.9

Correctif

2.6.10

Publication

01/02/2024

CVE-2023-7019 Moyenne · 4,3
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder

LightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 – Missing Authorization

The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including,…

Versions affectées

*-2.6.8

Correctif

2.6.9

Publication

05/01/2024

CVE-2022-1576 Élevée · 8,8
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder

WP Maintenance Mode & Coming Soon <= 2.4.4 – Cross-Site Request Forgery

The WP Maintenance Mode & Coming Soon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.4. This is due to missing nonce validation on the reset_plugin_settings, subscribers_empty_list, dismiss_notices, subscribers_export, add_subscriber, &…

Versions affectées

*-2.4.4

Correctif

2.4.5

Publication

20/06/2022

CVE-2013-3250 Moyenne · 5,4
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder

WP Maintenance Mode <= 1.8.7 – Missing Authorization Checks & Cross-Site Request Forgery

Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

Versions affectées

[*, 1.8.8)

Correctif

1.8.8

Publication

05/06/2013

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités