Extension WordPress

Vulnérabilités WP Extended – The Ultimate WordPress Toolkit

Cette page rassemble les failles publiées pour WP Extended – The Ultimate WordPress Toolkit, leurs plages de versions affectées et les correctifs signalés dans la base locale.

17Vulnérabilités
0Critiques
17Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Extended – The Ultimate WordPress Toolkit

17 fiches

CVE-2026-4314 Élevée · 8,8
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.2.4 – Authenticated (Subscriber+) Privilege Escalation via Menu Editor Module

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an…

Versions affectées

*-3.2.4

Correctif

3.2.5

Publication

21/03/2026

CVE-2025-4963 Moyenne · 6,4
WP Extended – The Ultimate WordPress Toolkit

WP Extended <= 3.0.15 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-3.0.15

Correctif

3.0.16

Publication

27/05/2025

CVE-2025-30796 Moyenne · 6,1
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.14 – Reflected Cross-Site Scripting

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.0.14

Correctif

3.0.15

Publication

27/03/2025

CVE-2024-13554 Moyenne · 5,3
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.13 – Missing Authorization to Unauthenticated Post Order Manipulation

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reorder_route() function in all versions up to, and including, 3.0.13. This makes…

Versions affectées

*-3.0.13

Correctif

3.0.14

Publication

11/02/2025

CVE-2024-13184 Élevée · 7,5
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 – Unauthenticated SQL Injection via Login Attempts Module

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied…

Versions affectées

*-3.0.12

Correctif

3.0.13

Publication

17/01/2025

CVE-2024-11816 Élevée · 8,8
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 – Missing Authorization to Authenticated (Subscriber+) Remote Code Execution

The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers,…

Versions affectées

*-3.0.11

Correctif

3.0.12

Publication

07/01/2025

CVE-2024-11916 Élevée · 7,4
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all versions up to, and including, 3.0.11. This…

Versions affectées

*-3.0.11

Correctif

3.0.12

Publication

07/01/2025

CVE-2024-9347 Moyenne · 6,1
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.9 – Reflected Cross-Site Scripting

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-3.0.9, 2.0.12, 3.0.11

Correctif

3.0.10, 3.0.13

Publication

16/10/2024

CVE-2024-47386 Moyenne · 6,1
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Reflected Cross-Site Scripting

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

30/09/2024

CVE-2024-8102 Élevée · 8,8
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Authenticated (Subscriber+) Arbitrary Options Update

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-8106 Moyenne · 6,5
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Authenticated (Subscriber+) Sensitive Information Exposure

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with Subscriber-level…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-8121 Moyenne · 5,4
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Missing Authorization to Admin Username Change

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user names due to a missing capability check on the wpext_change_admin_name() function in all versions up to, and including, 3.0.8. This…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-8123 Moyenne · 5,4
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Insecure Direct Object Reference

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due to missing validation on a user controlled…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-8119 Moyenne · 6,1
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Reflected Cross-Site Scripting via page

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-8104 Élevée · 8,8
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via the download_file_ajax function. This makes it possible for authenticated attackers, with subscriber access…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-8117 Moyenne · 6,1
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 – Reflected Cross-Site Scripting via selected_option

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘selected_option’ parameter in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-3.0.8

Correctif

3.0.9

Publication

03/09/2024

CVE-2024-37259 Moyenne · 6,1
WP Extended – The Ultimate WordPress Toolkit

The Ultimate WordPress Toolkit – WP Extended <= 2.4.7 – Unauthenticated Stored Cross-Site Scripting

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-2.4.7

Correctif

3.0.0

Publication

27/06/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités