Extension WordPress
Vulnérabilités WP-UserOnline
Cette page rassemble les failles publiées pour WP-UserOnline, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-UserOnline
4 fiches
WP-UserOnline <= 2.88.2 – Unauthenticated Stored Cross-Site Scripting
The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in all versions up to, and including, 2.88.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-2.88.2
2.88.3
06/11/2023
WP-UserOnline <= 2.88.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input,…
*-2.88.0
2.88.1
22/08/2022
WP-UserOnline <= 2.87.6 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][text]' parameter in versions up to, and including, 2.87.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
*-2.87.6
2.88.0
19/07/2022
WP-UserOnline < 2.70 – Cross-Site Scripting
The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-useronline.php file in versions up to, and including, 2.62 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.62
2.70
01/07/2010
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.