Extension WordPress
Vulnérabilités WP-PostRatings
Cette page rassemble les failles publiées pour WP-PostRatings, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-PostRatings
5 fiches
WP-PostRatings <= 1.91.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google rich text snippets in versions up to, and including, 1.91.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.91.1
1.91.2
01/08/2024
WP-PostRatings <= 1.91 – IP Spoofing
The WP-PostRatings plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.91. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login…
*-1.91
1.91.1
16/08/2023
WP-PostRatings <= 1.89 – Race Condition
The WP-PostRatings plugin for WordPress is vulnerable to Race Condition in versions up to, and including, 1.89. This can lead to unpredictable post rating changes when certain conditions are met.
*-1.89
1.90
31/08/2022
WP-PostRatings <= 1.86 – Cross-Site Scripting
The WP-PostRatings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postratings_image’ parameter in versions up to, and including, 1.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.86
1.86.1
24/12/2020
WP-PostRatings <= 1.61 – SQL Injection
SQL injection vulnerability in wp-postratings.php in the WP-PostRatings plugin 1.50, 1.61, and probably other versions before 1.62 for WordPress allows remote authenticated users with the Author role to execute arbitrary SQL commands via the id attribute of the…
*-1.61
1.62
06/10/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.