Extension WordPress

Vulnérabilités WebinarPress – Webinar System for WordPress

Cette page rassemble les failles publiées pour WebinarPress – Webinar System for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
0Critiques
5Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WebinarPress – Webinar System for WordPress

10 fiches

CVE-2025-47635 Moyenne · 5,5
WebinarPress – Webinar System for WordPress

WebinarPress <= 1.33.27 – Authenticated (Administrator+) Server-Side Request Forgery

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.33.27. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…

Versions affectées

*-1.33.27

Correctif

Non indiqué

Publication

07/05/2025

CVE-2025-31883 Moyenne · 4,4
WebinarPress – Webinar System for WordPress

WebinarPress <= 1.33.27 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WebinarPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.33.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…

Versions affectées

*-1.33.27

Correctif

Non indiqué

Publication

01/04/2025

CVE-2024-11270 Élevée · 8,8
WebinarPress – Webinar System for WordPress

WordPress Webinar Plugin – WebinarPress <= 1.33.24 – Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24.…

Versions affectées

*-1.33.24

Correctif

1.33.25

Publication

07/01/2025

CVE-2024-11271 Élevée · 8,8
WebinarPress – Webinar System for WordPress

WordPress Webinar Plugin – WebinarPress <= 1.33.24 – Missing Authorization to Authenticated (Subscriber+) Webinar Updates

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated…

Versions affectées

*-1.33.24

Correctif

1.33.25

Publication

07/01/2025

CVE-2024-34818 Moyenne · 4,3
WebinarPress – Webinar System for WordPress

WordPress Webinar Plugin – WebinarPress <= 1.33.20 – Cross-Site Request Forgery

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.33.20. This is due to missing or incorrect nonce validation on the wswebinar_duplicate_post_as_draft() function. This makes…

Versions affectées

*-1.33.20

Correctif

1.33.21

Publication

09/05/2024

CVE-2024-31256 Moyenne · 6,1
WebinarPress – Webinar System for WordPress

WebinarPress <= 1.33.9 – Reflected Cross-Site Scripting

The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.33.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.33.9

Correctif

1.33.10

Publication

05/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités