Extension WordPress
Vulnérabilités WPPizza – A Restaurant Plugin
Cette page rassemble les failles publiées pour WPPizza – A Restaurant Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPPizza – A Restaurant Plugin
8 fiches
WPPizza – A Restaurant Plugin <= 3.19.9 – Authenticated (Subscriber+) Information Exposure
The WPPizza – A Restaurant Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.19.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive…
*-3.19.9
3.20
29/04/2026
WPPizza <= 3.19.8 – Missing Authorization
The WPPizza – A Restaurant Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.19.8. This makes it possible for authenticated attackers,…
*-3.19.8
3.19.8.1
22/08/2025
WPPizza <= 3.19.4 – Reflected Cross-Site Scripting
The WPPizza plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.19.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-3.19.4
3.19.5
23/02/2025
WPPizza – A Restaurant Plugin <= 3.18.13 – Reflected Cross-Site Scripting
The WPPizza – A Restaurant Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.18.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.18.13
3.18.14
18/06/2024
WPPizza <= 3.18.10 – Missing Authorization
The WPPizza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_ajax function found in several files in versions up to, and including, 3.18.10. This makes it possible for…
*-3.18.10
3.18.11
25/04/2024
WPPizza <= 3.18.2 – Reflected Cross-Site Scripting
The WPPizza plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the use of PHP_SELF in versions up to, and including, 3.18.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.18.2
3.18.3
25/10/2023
WPPizza <= 3.17.1 – Reflected Cross-Site Scripting
The WPPizza plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple GET parameters in versions up to, and including, 3.17.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.17.1
3.17.2
03/05/2023
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[*, 2.11.8.18)
2.11.8.18
01/08/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.