Thème WordPress
Vulnérabilités Newspaper – News & WooCommerce WordPress Theme
Cette page rassemble les failles publiées pour Newspaper – News & WooCommerce WordPress Theme, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Newspaper – News & WooCommerce WordPress Theme
9 fiches
Newspaper <= 12.6.5 – Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta
The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-12.6.5
12.6.6
18/04/2024
tagDiv Cloud Library < 2.7 – Missing Authorization to Arbitrary User Metadata Update
The tagDiv Cloud Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tdb_user_form_on_submit() function called via an AJAX action in versions prior to 2.7. This makes it possible…
*-12.3
12.4
19/06/2023
tagDiv Composer < 3.5 – Unauthorized Account Access and Privilege Escalation
The tagDiv Composer plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, but not including, 3.5 due to improper implementation of the Facebook login feature. This allows unauthenticated attackers to log…
*-12
12.1
24/10/2022
Newspaper <= 11.5.1 – Reflected Cross-Site Scripting
The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, and including, 11.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-11.5.1
12
10/10/2022
Newspaper <= 11.5.1 – Reflected Cross-Site Scripting
The Newspaper theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an AJAX action in versions up to, and including, 11.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-11.5.1
12
10/10/2022
Newspaper <= 10.3.3 – Reflected Cross-Site Scripting
The Newspaper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 10.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-10.3.3
10.3.4
03/06/2020
Newspaper < 9.2.2 – Cross-Site Scripting
The Newspaper theme for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute…
[*, 9.2.2)
9.2.2
14/02/2019
Newspaper – News & WooCommerce WordPress Theme <= 6.7 – Arbitrary Options Update
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
*-6.7.1
6.7.2
06/06/2016
Newspaper – News & WooCommerce WordPress Theme < 6.7.2 – Cross-Site Scripting
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
[*, 6.7.2)
6.7.2
06/06/2016
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.