Extension WordPress
Vulnérabilités WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel, page 2
Cette page rassemble les failles publiées pour WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel
27 fiches
Easy Drag And drop All Import : WP Ultimate CSV Importer < 6.4.1 – Missing Authorization Checks
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions like upload_function(), display_log(), download_log(), display_csv_values(), etc… in versions up to 6.4.1. This makes it possible for…
[*, 6.4.1)
6.4.1
12/01/2022
Easy Drag And drop All Import : WP Ultimate CSV Importer <= 5.6 – Cross-Site Request Forgery
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
*-5.6
5.6.1
13/08/2019
Import Export All WordPress Images, Users & Post Types <= 3.8.7 – Reflected Cross-Site Scripting
The Import Export All WordPress Images, Users & Post Types plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘alertmsg’ parameter in versions up to, and including, 3.8.7 due to insufficient input sanitization and output escaping.…
[*, 3.8.8)
3.8.8
27/01/2018
Easy Drag And drop All Import : WP Ultimate CSV Importer < 3.8.1 – Cross-Site Scripting
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
[*, 3.8.1)
3.8.1
18/08/2015
Import CSV or XML Datafeed With Ease <= 3.7.2 – Cross-Site Request Forgery
The Import CSV or XML Datafeed With Ease plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.7.2. This is due to missing or incorrect nonce validation on several functions. This…
*-3.7.2
3.7.3
05/05/2015
WP Ultimate CSV Importer <= 3.7 – Arbitrary File Read
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the templates/readfile.php file in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to…
*-3.7
3.7.1
27/04/2015
Ultimate CSV Importer < 3.6.75 – Information Disclosure
The Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.6.74 via the modules/export/templates/export.php file. This can allow unauthenticated attackers to extract sensitive data including emails, passwords and usernames.
[*, 3.6.75)
3.6.75
22/02/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.