Extension WordPress
Vulnérabilités WP Pipes
Cette page rassemble les failles publiées pour WP Pipes, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Pipes
9 fiches
WP Pipes <= 1.4.3 – Reflected Cross-Site Scripting
The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.4.3
Non indiqué
14/08/2025
WP Pipes <= 1.4.3 – Unauthenticated Local File Inclusion
The WP Pipes plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
*-1.4.3
Non indiqué
22/07/2025
WP Pipes <= 1.4.3 – Unauthenticated SQL Injection
The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
*-1.4.3
Non indiqué
08/07/2025
WP Pipes <= 1.4.3 – Unauthenticated Arbitrary File Deletion
The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 1.4.3. This makes it possible for unauthenticated attackers to delete arbitrary files on…
*-1.4.3
Non indiqué
06/07/2025
WP Pipes <= 1.4.2 – Unauthenticated Arbitrary File Deletion
The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via the delete_template() function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to…
*-1.4.2
1.4.3
30/05/2025
WP Pipes <= 1.4.3 – Authenticated (Administrator+) Server-Side Request Forgery
The WP Pipes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary…
*-1.4.3
Non indiqué
07/05/2025
WP Pipes <= 1.4.1 – Reflected Cross-Site Scripting via x1 Parameter
The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.4.1
1.4.2
10/12/2024
WP Pipes <= 1.4.0 – Cross-Site Request Forgery to Settings Update
The WP Pipes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the save() function. This makes it possible for unauthenticated attackers to…
[*, 1.4.1)
1.4.1
11/08/2023
WP Pipes <= 1.33 – Authenticated (Admin+) SQL Injection
The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
1.0, 1.1, 1.10, 1.11, 1.12, 1.13, 1.14, 1.15, 1.16, 1.17, 1.18, 1.19, 1.2, 1.20, 1.21, 1.22, 1.23, 1.24, 1.25, 1.26, 1.27, 1.28, 1.29, 1.3, 1.30, 1.31, 1.32, 1.33, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9
1.4.0
20/12/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.