Extension WordPress
Vulnérabilités WS Form Pro
Cette page rassemble les failles publiées pour WS Form Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WS Form Pro
4 fiches
WS Form LITE and PRO <= 1.10.13 – Unauthenticated Stored Cross-Site Scripting
The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in all versions up to, and including, 1.10.13 due to insufficient input sanitization and output escaping. This makes it…
*-1.10.13
1.10.14
27/01/2025
WS Form LITE <= 1.9.217 – Unauthenticated CSV Injection
The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when…
*-1.9.217
1.9.218
06/06/2024
WS Form LITE and WS Form Pro < 1.8.176 – Stored Cross-Site Scripting
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
[*, 1.8.176)
1.8.176
31/01/2022
WS Form LITE and Pro < 1.8.176 – Stored Cross-Site Scripting
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
[*, 1.8.176)
1.8.176
31/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.