Extension WordPress
Vulnérabilités WPQA – Builder forms Addon For WordPress
Cette page rassemble les failles publiées pour WPQA – Builder forms Addon For WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPQA – Builder forms Addon For WordPress
10 fiches
WPQA – Builder forms Addon For WordPress plugin <= 6.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WPQA – Builder forms Addon For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via slider settings in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping. This makes…
*-6.1.0
6.1.1
12/06/2024
WPQA Builder <= 6.1.0 – Cross-Site Request Forgery
The WPQA Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for…
*-6.1.0
6.1.1
12/06/2024
WPQA – Builder forms Addon For WordPress (<= 5.9.2), Himer (<= 1.9.3) and Discy (<= 5.5.3) – Authenticated (Subscriber+) Insecure Direct Object Reference
The WPQA – Builder forms Addon For WordPress plugin is vulnerable to insecure direct object reference in versions up to, and including, 5.9.2 along with the Himer (
*-5.9.2
5.9.3
13/12/2022
WPQA < 5.9 – Cross-Site Request Forgery
The WPQA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 5.9. This is due to missing or incorrect nonce validation on some of its functions. This makes it possible for…
[*, 5.9)
5.9
25/10/2022
WPQA – Builder forms Addon For WordPress < 5.7 – Information Disclosure
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any logged in user to read other users private message using…
[*, 5.7)
5.7
01/08/2022
WPQA – Builder forms Addon For WordPress <= 5.3 – Reflected Cross-Site Scripting
The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting…
[*, 5.4)
5.4
10/05/2022
WPQA – Builder forms Addon For WordPress <= 5.4 – Unauthenticated Private Message Disclosure
The WPQA Builder WordPress plugin before 5.4 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.
*-5.4
5.5
10/05/2022
WPQA – Builder forms Addon For WordPress < 5.2 – Insecure Direct Object Reference to Profile Picture Deletion
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the…
[*, 5.2)
5.2
21/04/2022
WPQA – Builder forms Addon For WordPress < 5.2 – Insecure Direct Object Reference to Private Message Disclosure
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax action belongs to the requesting user, leading to any…
[*, 5.2)
5.2
21/04/2022
WPQA – Builder forms Addon For WordPress < 5.2 – Stored Cross-Site Scripting via Profile fields
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page,…
[*, 5.2)
5.2
21/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.