Extension WordPress
Vulnérabilités WP Extended – The Ultimate WordPress Toolkit
Cette page rassemble les failles publiées pour WP Extended – The Ultimate WordPress Toolkit, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Extended – The Ultimate WordPress Toolkit
17 fiches
The Ultimate WordPress Toolkit – WP Extended <= 3.2.4 – Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module
The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an…
*-3.2.4
3.2.5
21/03/2026
WP Extended <= 3.0.15 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.0.15
3.0.16
27/05/2025
The Ultimate WordPress Toolkit – WP Extended <= 3.0.14 – Reflected Cross-Site Scripting
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.0.14
3.0.15
27/03/2025
The Ultimate WordPress Toolkit – WP Extended <= 3.0.13 – Missing Authorization to Unauthenticated Post Order Manipulation
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() function in all versions up to, and including, 3.0.13. This makes…
*-3.0.13
3.0.14
11/02/2025
The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 – Unauthenticated SQL Injection via Login Attempts Module
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied…
*-3.0.12
3.0.13
17/01/2025
The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 – Missing Authorization to Authenticated (Subscriber+) Remote Code Execution
The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers,…
*-3.0.11
3.0.12
07/01/2025
The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all versions up to, and including, 3.0.11. This…
*-3.0.11
3.0.12
07/01/2025
The Ultimate WordPress Toolkit – WP Extended <= 3.0.9 – Reflected Cross-Site Scripting
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This…
*-3.0.9, 2.0.12, 3.0.11
3.0.10, 3.0.13
16/10/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Reflected Cross-Site Scripting
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.0.8
3.0.9
30/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Authenticated (Subscriber+) Arbitrary Options Update
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Authenticated (Subscriber+) Sensitive Information Exposure
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with Subscriber-level…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Missing Authorization to Admin Username Change
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. This…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Insecure Direct Object Reference
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due to missing validation on a user controlled…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Reflected Cross-Site Scripting via page
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes it possible for authenticated attackers, with subscriber access…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Reflected Cross-Site Scripting via selected_option
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This…
*-3.0.8
3.0.9
03/09/2024
The Ultimate WordPress Toolkit – WP Extended <= 2.4.7 – Unauthenticated Stored Cross-Site Scripting
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-2.4.7
3.0.0
27/06/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.