Extension WordPress
Vulnérabilités Connect Matomo – Analytics Dashboard for WordPress
Cette page rassemble les failles publiées pour Connect Matomo – Analytics Dashboard for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Connect Matomo – Analytics Dashboard for WordPress
5 fiches
WP-Matomo Integration (WP-Piwik) <= 1.0.28 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp-piwik' shortcode in versions up to, and including, 1.0.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.0.28
1.0.29
21/09/2023
WP-Piwik <= 1.0.27 – Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Display Name
The WP-Piwik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin display name in versions up to, and including, 1.0.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.0.27
1.0.28
22/05/2023
WP-Matomo Integration (WP-Piwik) <= 1.0.26 – Cross-Site Request Forgery
The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.26. This is due to missing nonce validation on the show() function which makes it possible for unauthenticated attackers…
[*, 1.0.27)
1.0.27
07/02/2022
WP-Matomo Integration (WP-Piwik) < 1.0.11 – Unauthenticated Stored Cross-Site Scripting
The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp-piwik’ parameter in versions before 1.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-1.0.10
1.0.11
02/09/2016
WP-Matomo Integration (WP-Piwik) < 1.0.5 – Cross-Site Scripting
The wp-piwik plugin before 1.0.5 for WordPress has XSS.
[*, 1.0.5)
1.0.5
13/10/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.