Extension WordPress
Vulnérabilités WP-Recall – Registration, Profile, Commerce & More
Cette page rassemble les failles publiées pour WP-Recall – Registration, Profile, Commerce & More, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-Recall – Registration, Profile, Commerce & More
17 fiches
WP-Recall <= 16.26.14 – Reflected Cross-Site Scripting
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 16.26.14 due to insufficient input sanitization and output escaping. This makes it possible for…
*-16.26.14
Non indiqué
26/06/2025
WP-Recall <= 16.26.14 – Missing Authorization
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 16.26.14. This makes it possible for…
*-16.26.14
Non indiqué
19/06/2025
WP-Recall <= 16.26.14 – Cross-Site Request Forgery
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 16.26.14. This is due to missing or incorrect nonce validation on a function. This…
*-16.26.14
Non indiqué
05/06/2025
WP-Recall <= 16.26.14 – Authenticated (Contributor+) Local File Inclusion
The WP-Recall plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 16.26.14. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-16.26.14
Non indiqué
07/05/2025
WP-Recall <= 16.26.11 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP-Recall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 16.26.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-16.26.11
16.26.12
07/04/2025
WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 – Unauthenticated SQL Injection
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and…
*-16.26.10
16.26.12
07/03/2025
WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX endpoint in all versions up to, and including, 16.26.10. This makes…
*-16.26.10
16.26.12
07/03/2025
WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 – Authenticated (Contributor+) Protected Post Disclosure
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'feed' shortcode due to insufficient restrictions on which posts can be included.…
*-16.26.10
16.26.12
07/03/2025
WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up to, and including, 16.26.10 due to insufficient input sanitization and output escaping…
*-16.26.10
16.26.12
07/03/2025
WP-Recall – Registration, Profile, Commerce & More <= 16.26.11 – Authenticated (Admin+) SQL Injection
The WP-Recall plugin for WordPress is vulnerable to SQL Injection via the 'product[fields]' parameter in all versions up to, and including, 16.26.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-16.26.11
16.26.12
03/03/2025
WP-Recall – Registration, Profile, Commerce & More <= 16.26.8 – Insecure Direct Object Reference to Unauthenticated Arbitrary Password Update
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's identity during…
*-16.26.8
16.26.9
05/09/2024
WP-Recall – Registration, Profile, Commerce & More <= 16.26.6 – Unauthenticated Payment Deletion via delete_payment
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_payment' function in all versions up to, and including, 16.26.6. This makes…
*-16.26.6
16.26.7
05/06/2024
WP-Recall <= 16.26.6 – Cross-Site Request Forgery
The WP-Recall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 16.26.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…
*-16.26.6
16.26.7
03/06/2024
WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 – Unauthenticated SQL Injection
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 16.26.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-16.26.5
16.26.6
22/04/2024
WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 – Authenticated (Contributor+) SQL Injection
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 16.26.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-16.26.5
16.26.6
22/04/2024
WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 – Insecure Direct Object Reference
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 16.26.5 due to missing validation on a user controlled key. This makes it…
*-16.26.5
16.26.6
16/04/2024
WP-Recall <= 16.24.47 – Reflected Cross-Site Scripting
The WP-Recall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date-start' and 'end-start' parameters in versions up to, and including, 16.24.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-16.24.47
16.24.48
05/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.