発見した脆弱性一覧

WordPress 用プラグイン

脆弱性解説の有無プラグイン名プラグインスラッグ影響を受けるバージョン脆弱性CVE番号CVSS脆弱性情報公開日ステータス
YesFile Managerwp-file-manager<= 7.2.1Sensitive Information Exposure via Backup FilenamesCVE-2024-07618.12024/01/22修正済み
NoCleverwise Daily Quotescleverwise-daily-quotes<= 3.2Reflected Cross-Site ScriptingCVE-2023-403357.22023/08/17公開停止
NoSimple Staff Listsimple-staff-list<= 2.2.3Authenticated (Editor+) Stored Cross-Site ScriptingCVE-2023-287904.42023/08/17修正済み
NoArt Directionart-direction<= 0.2.4Authenticated (Contributor+) Stored Cross-Site ScriptingCVE-2023-379836.42023/07/12公開停止
NoReplace Wordreplace-word<= 2.1Cross-Site Request ForgeryCVE-2023-379734.32023/07/12公開停止
NoSimple Light Weight Social Share (Tweet, Like, Share and Linkedin)only-tweet-like-share-and-google-1<= 2.0Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-373884.42023/07/05公開停止
NoSide Cart Woocommerce (Ajax)side-cart-woocommerce<= 2.2Authenticated(Administrator+) Stored Cross-Site ScriptingCVE-2023-284154.42023/06/28修正済み
NoJS Job Managerjs-jobs<= 2.0.0Cross-Site Request Forgery via multiple functionsCVE-2023-310875.42023/06/02修正済み
NoFloating Action Buttonfloating-action-button<=1.2.1Cross-Site Request Forgery to Settings ModificationCVE-2023-310884.32023/05/31修正済み
NoHeadless CMSheadless-cms<= 2.0.3Missing AuthorizationCVE-2023-341866.52023/05/30公開停止
NoSKU Label Changer For WooCommercewoo-sku-label-changer<= 3.0Missing AuthorizationCVE-2023-291745.32023/05/25公開停止
NoSmart App Bannersmart-app-banner<= 1.1.2Cross-Site Request Forgery via wsl_smart_app_banner_optionsCVE-2023-333155.42023/05/21修正済み
NoCALL ME NOWlokalyze-call-now<= 3.0Cross-Site Request ForgeryCVE-2023-326024.32023/05/12公開停止
NoPlugins Listplugins-list<= 2.5Authenticated (Author+) Stored Cross-Site Scripting via replace_plugin_list_tagsCVE-2023-312326.42023/04/28修正済み
NoEasy Beteasy-bet<= 1.0.2Authenticated(Contributor+) SQL InjectionCVE-2023-310928.82023/04/26公開停止
NoLogo Schedulerlogo-scheduler-great-for-holidays-events-and-more<= 1.2.0Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-308754.42023/04/26修正済み
NoWoocommerce Tip/Donationwoo-tipdonation<= 1.2Authenticated (Shop manager+) Stored Cross-Site Scripting via plugin settingsCVE-2023-287835.52023/04/24公開停止
NoDisplay custom fields in the frontend – Post and User Profile Fieldsshortcode-to-display-post-and-user-data<= 1.2.0Missing Authorization via vg_display_data shortcodeCVE-2023-310736.52023/04/24修正済み
NoWoocommerce Email Reportwooemailreport<= 2.4Unauthenticated Cross-Site ScriptingCVE-2023-276276.12023/04/21公開停止
NoEasy Slider Revolutioneasy-slider-revolution<= 1.0.0Authenticated (Author+) Stored Cross-Site Scripting via esrcpt_slider_allow_iframes_filterCVE-2023-286226.42023/04/21公開停止
NoDave’s WordPress Live Searchdaves-wordpress-live-search<= 4.8.1Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-308764.42023/04/21公開停止
NoGPS Plottergps-plotter<= 5.2.0Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-308744.42023/04/21公開停止
NoCab Gridcab-grid<= 1.5.15Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-285334.42023/04/21修正済み
NoeRocketerocket<= 1.2.4Authenticated (Administrator+) Stored Cross-Site ScriptingCVE-2023-281744.42023/04/21修正済み
NoRedirect After Loginredirect-after-login<= 0.1.9Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settingsCVE-2023-276244.42023/04/21公開停止
NoApexChatapexchat<= 1.3.1Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settingsCVE-2023-284144.42023/04/18修正済み
NoCaptcha Them Allcaptcha-them-all<= 1.3.3Authenticated (Admin+) Stored Cross-Site ScriptingCVE-2023-307864.42023/04/18修正済み
Noa3 Portfolioa3-portfolio<= 3.1.0Authenticated (Author+) Stored Cross-Site ScriptingCVE-2023-290976.42023/04/10修正済み
NoMobile Bannermobile-banner<= 1.5Cross-Site Request Forgery leading to Plugin Settings ChangesCVE-2023-289304.32023/03/29修正済み
NoEnhanced Plugin Adminenhanced-plugin-admin<= 1.16Cross-Site Request Forgery via epa_options_pageCVE-2023-286185.42023/03/21修正済み
NoEvent Manager for WooCommercemage-eventpress<= 3.8.6Authenticated (Administrator+) Stored Cross-Site Scripting via ‘mep_get_option’ functionCVE-2023-284224.42023/03/20修正済み
NoBranded Social Imagesbranded-social-images<= 1.1.0Missing Authorization leading to Unauthenticated Plugin Settings UpdatesCVE-2023-285365.32023/03/20修正済み