Extension WordPress
Vulnérabilités WebinarPress – Webinar System for WordPress
Cette page rassemble les failles publiées pour WebinarPress – Webinar System for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WebinarPress – Webinar System for WordPress
10 fiches
WebinarPress <= 1.33.28 – Missing Authorization
The WebinarPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.33.28. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-1.33.28
Non indiqué
19/10/2025
WebinarPress <= 1.33.27 – Authenticated (Administrator+) Server-Side Request Forgery
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.33.27. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…
*-1.33.27
Non indiqué
07/05/2025
WebinarPress <= 1.33.27 – Open Redirect
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.33.27. This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated…
*-1.33.27
Non indiqué
09/04/2025
WebinarPress <= 1.33.27 – Missing Authorization
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.33.27. This makes it possible for authenticated attackers,…
*-1.33.27
Non indiqué
01/04/2025
WebinarPress <= 1.33.27 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WebinarPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.33.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
*-1.33.27
Non indiqué
01/04/2025
WordPress Webinar Plugin – WebinarPress <= 1.33.24 – Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24.…
*-1.33.24
1.33.25
07/01/2025
WordPress Webinar Plugin – WebinarPress <= 1.33.24 – Missing Authorization to Authenticated (Subscriber+) Webinar Updates
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated…
*-1.33.24
1.33.25
07/01/2025
WebinarPress <= 1.33.20 – Cross-Site Request Forgery
The WebinarPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.33.20. This is due to missing or incorrect nonce validation on the embedded_iframe() function. This makes it possible for unauthenticated attackers…
*-1.33.20
1.33.21
16/08/2024
WordPress Webinar Plugin – WebinarPress <= 1.33.20 – Cross-Site Request Forgery
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.33.20. This is due to missing or incorrect nonce validation on the wswebinar_duplicate_post_as_draft() function. This makes…
*-1.33.20
1.33.21
09/05/2024
WebinarPress <= 1.33.9 – Reflected Cross-Site Scripting
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.33.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.33.9
1.33.10
05/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.