Extension WordPress
Vulnérabilités WpStream – Live Streaming, Video on Demand, Pay Per View
Cette page rassemble les failles publiées pour WpStream – Live Streaming, Video on Demand, Pay Per View, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WpStream – Live Streaming, Video on Demand, Pay Per View
6 fiches
WpStream – Live Streaming, Video on Demand, Pay Per View < 4.11.2 – Authenticated (Subscriber+) Arbitrary File Upload
The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to 4.11.2 (exclusive). This makes it possible for…
[*, 4.11.2)
4.11.2
17/04/2026
WpStream < 4.11.2 – Authenticated (Subscriber+) Insecure Direct Object Reference
The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 4.11.2 (exclusive) due to missing validation on a user controlled key. This…
[*, 4.11.2)
4.11.2
11/03/2026
WpStream <= 4.9.5 – Missing Authorization
The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.5. This makes…
*-4.9.5
4.9.6
30/12/2025
WpStream <= 4.9.5 – Missing Authorization
The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.5. This makes…
*-4.9.5
4.9.6
29/12/2025
WpStream – Live Streaming, Video on Demand, Pay Per View <= 4.5.4 – Cross-Site Request Forgery via wpstream_update_local_event_settings
The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.4. This is due to missing or incorrect nonce validation on the…
*-4.5.4
4.5.5
20/07/2023
WpStream – Live Streaming, Video on Demand, Pay Per View <= 4.4.10 – Cross-Site Request Forgery via wpstream_settings
The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.10. This is due to missing or incorrect nonce validation on the…
*-4.4.10
4.4.10.6
02/03/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.