Extension WordPress

Vulnérabilités WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress

Cette page rassemble les failles publiées pour WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
2Critiques
3Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress

3 fiches

CVE-2025-66074 Critique · 9,8
WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress

Webhooks <= 3.3.8 – Unauthenticated Arbitrary File Upload

The WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.3.8.…

Versions affectées

*-3.3.8

Correctif

3.3.9

Publication

12/12/2025

CVE-2025-66073 Moyenne · 6,6
WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress

Webhooks <= 3.3.8 – Authenticated (Administrator+) PHP Object Injection

The Webhooks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.8 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a…

Versions affectées

*-3.3.8

Correctif

3.3.9

Publication

26/11/2025

CVE-2025-8895 Critique · 9,8
WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress

WP Webhooks <= 3.3.5 – Unauthenticated Arbitrary File Copy

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files…

Versions affectées

*-3.3.5

Correctif

3.3.6

Publication

20/08/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités