Extension WordPress

Vulnérabilités Photo Engine (Media Organizer & Lightroom)

Cette page rassemble les failles publiées pour Photo Engine (Media Organizer & Lightroom), leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Photo Engine (Media Organizer & Lightroom)

5 fiches

CVE-2026-32524 Élevée · 8,8
Photo Engine (Media Organizer & Lightroom)

Photo Engine (Media Organizer & Lightroom) <= 6.4.9 – Authenticated (Author+) Arbitrary File Upload

The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers, with…

Versions affectées

*-6.4.9

Correctif

6.5.0

Publication

20/03/2026

CVE-2024-39660 Moyenne · 6,4
Photo Engine (Media Organizer & Lightroom)

Photo Engine <= 6.3.1 – Authenticated (Author+) Stored Cross-Site Scripting

The Photo Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…

Versions affectées

*-6.3.1

Correctif

6.3.2

Publication

01/08/2024

CVE-2023-38513 Moyenne · 5,4
Photo Engine (Media Organizer & Lightroom)

Photo Engine <= 6.2.5 – Authenticated (Author+) Insecure Direct Object Reference in ajax_generate_auth_token

The Photo Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.5. This is due to missing validation on a user controlled key within the ajax_generate_auth_token function. This makes it…

Versions affectées

*-6.2.5

Correctif

6.2.6

Publication

20/07/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités