Extension WordPress
Vulnérabilités YourChannel: Everything you want in a YouTube plugin.
Cette page rassemble les failles publiées pour YourChannel: Everything you want in a YouTube plugin., leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YourChannel: Everything you want in a YouTube plugin.
10 fiches
YourChannel <= 1.2.5 – Authenticated (Administrator+) Stored Cross-Site Scripting
The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level…
*-1.2.5
1.2.6
18/04/2023
YourChannel <= 1.2.4 – Cross-Site Request Forgery to Plugin Language Translation Reset
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on the deleteLang function. This makes it possible for unauthenticated attackers…
*-1.2.4
1.2.5
05/04/2023
YourChannel <= 1.2.4 – Cross-Site Request Forgery to Plugin Language Translation Update
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on the saveLang function. This makes it possible for unauthenticated attackers…
*-1.2.4
1.2.5
05/04/2023
YourChannel <= 1.2.3 – Missing Authorization to Plugin Cache Reset
The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when clearing the plugin cache via the yrc_clear_cache GET parameter in versions up to, and including, 1.2.3. This makes it…
*-1.2.3
1.2.4
05/04/2023
YourChannel <= 1.2.4 – Cross-Site Request Forgery to Plugin Settings Change
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers…
*-1.2.4
1.2.5
05/04/2023
YourChannel <= 1.2.4 – Cross-Site Request Forgery to Plugin Channel Reset
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on the clearKeys function. This makes it possible for unauthenticated attackers…
*-1.2.4
1.2.5
05/04/2023
YourChannel <= 1.2.3 – Missing Authorization to Plugin Settings Reset
The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when resetting plugin settings via the yrc_nuke GET parameter in versions up to, and including, 1.2.3. This makes it possible…
*-1.2.3
1.2.4
05/04/2023
YourChannel <= 1.2.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'yrc_lang[Videos]'
The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘yrc_lang[Videos]’ parameter in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.2.1
1.2.2
13/01/2023
YourChannel <= 1.2.1 – Missing Authorization Checks leading to Authenticated (Subscriber+) Stored Cross-Site Scripting
The YourChannel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'save', 'delete', 'deleteLang', and 'saveLang' functions in versions up to, and including, 1.2.1. This could lead to Cross-Site Scripting due to…
*-1.2.1
1.2.2
13/01/2023
YourChannel <= 1.2.2 Authenticated (Contributor+) Cross-Site Scripting via Shortcode
The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-1.2.2
1.2.3
10/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.