Thème WordPress
Vulnérabilités CozyStay – Hotel Booking WordPress Theme
Cette page rassemble les failles publiées pour CozyStay – Hotel Booking WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CozyStay – Hotel Booking WordPress Theme
5 fiches
CozyStay < 1.9.1 – Unauthenticated Local File Inclusion
The CozyStay theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.9.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP…
[*, 1.9.1)
1.9.1
05/02/2026
CozyStay < 1.7.1 – Unauthenticated Local File Inclusion
The CozyStay theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.7.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP…
[*, 1.7.1)
1.7.1
11/06/2025
CozyStay < 1.7.1 – Unauthenticated PHP Object Injection
The CozyStay theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.7.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is…
[*, 1.7.1)
1.7.1
09/06/2025
CozyStay <= 1.7.0 – Missing Authorization to Arbitrary Action Execution in ajax_handler
The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to…
*-1.7.0
1.7.1
18/03/2025
CozyStay <= 1.7.0 and TinySalt <= 3.9.0 – Unauthenticated PHP Object Injection in ajax_handler
The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and including, 1.7.0, and in all versions up to, and including 3.9.0, respectively, via deserialization of untrusted input in the…
*-1.7.0
1.7.1
18/03/2025
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.