Extension WordPress
Vulnérabilités WPIDE – File Manager & Code Editor
Cette page rassemble les failles publiées pour WPIDE – File Manager & Code Editor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPIDE – File Manager & Code Editor
7 fiches
WPIDE – File Manager & Code Editor <= 3.5.6 – Cross-Site Request Forgery
The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.6. This is due to missing or incorrect nonce validation on a function. This makes…
*-3.5.6
Non indiqué
02/07/2026
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-3.5.1
3.5.2
30/04/2026
WPIDE <= 3.4.9 – Unauthenticated Full Path Dislcosure
The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser…
*-3.4.9
3.5.0
14/10/2024
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
3.0-3.4.6
3.4.7
18/07/2023
WPide <= 2.6 – Authenticated (Administrator+) Arbitrary File Upload
The WPide plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.6. This makes it possible for authenticated attackers, with administrator-level permissions and above, to upload arbitrary files on the affected sites…
*-2.6
3.0
09/08/2022
WPide <= 2.6 – Authenticated (Administrator+) Arbitrary File Read
The plugin WPide for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.6. This makes it possible for authenticated users, with administrative privileges or higher, to read any file on the server.
*-2.6
3.0
09/08/2022
WPIDE – File Manager & Code Editor <= 2.6 – Authenticated (Admininstrator+) Local File Inclusion
The WPIDE plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6. This allows administrator-level or higher attackers to include and execute arbitrary files on the server, allowing the execution of any…
*-2.6
3.0
03/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.