Extension WordPress
Vulnérabilités YITH Essential Kit for WooCommerce #1
Cette page rassemble les failles publiées pour YITH Essential Kit for WooCommerce #1, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YITH Essential Kit for WooCommerce #1
3 fiches
YITH Essential Kit for WooCommerce #1 <= 2.34.0 – Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation
The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_module', 'deactivate_module', and 'install_module' functions in all versions up to, and including, 2.34.0.…
*-2.34.0
2.35.0
18/07/2024
YITH plugins by YITHEMES <= (Various Versions) – Cross-Site Request Forgery
Several YITHEMES plugins for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the create_log_file function. This makes it possible for unauthenticated attackers to create an error or debug log…
*-2.13.0
2.14.0
11/11/2022
YITH plugins by YITHEMES <= (Various Versions) – Missing Authorization
Several YITHEMES plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the create_log_file function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the logs of the…
*-2.13.0
2.14.0
11/11/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.