Thème WordPress
Vulnérabilités AdForest
Cette page rassemble les failles publiées pour AdForest, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de AdForest
8 fiches
AdForest <= 6.0.12 – Authentication Bypass
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function.…
*-6.0.12
6.0.13
11/02/2026
AdForest <= 6.0.11 – Unauthenticated Local File Inclusion
The AdForest theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.0.11. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
*-6.0.11
6.0.12
20/01/2026
AdForest <= 6.0.11 – Missing Authorization
The AdForest theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.0.11. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-6.0.11
6.0.12
04/12/2025
AdForest <= 6.0.9 – Authentication Bypass to Admin
The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible…
*-6.0.9
6.0.10
05/09/2025
AdForest <= 5.1.8 – Authentication Bypass
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user.…
*-5.1.8
5.1.9
21/01/2025
AdForest – Classified Ads WordPress Theme <= 5.1.7 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post/Attachment Deletion
The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions up to, and including, 5.1.7. This makes it possible for authenticated…
*-5.1.7
5.1.8
07/01/2025
AdForest <= 5.1.6 – Privilege Escalation via Password Reset/Account Takeover
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password…
*-5.1.6
5.1.7
20/12/2024
AdForest <= 5.1.6 – Authentication Bypass
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function.…
*-5.1.6
5.1.7
20/12/2024
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.