Extension WordPress
Vulnérabilités Comments – wpDiscuz, page 2
Cette page rassemble les failles publiées pour Comments – wpDiscuz, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Comments – wpDiscuz
25 fiches
Comments – wpDiscuz <= 7.3.3 – Arbitrary Comment Addition/Edition/Deletion by Cross-Site Request Forgery
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made…
[*, 7.3.4)
7.3.4
11/10/2021
Comments – wpDiscuz <= 7.3.0 – Authenticated Stored Cross-Site Scripting
The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitize or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even…
*-7.3.0
7.3.2
13/09/2021
Comments – wpDiscuz 7.0 – 7.0.4 – Unauthenticated Arbitrary File Upload leading to Remote Code Execution
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
7.0-7.0.4
7.0.5
06/06/2021
Comments – wpDiscuz <= 5.3.5 – Blind SQL Injection via order Parameter
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
[*, 5.3.6)
5.3.6
12/06/2020
Comments – wpDiscuz <= 3.1.4 – Reflected Cross-Site Scripting
The Comments – wpDiscuz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ parameter in versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.1.4
3.2.0
30/05/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.