{"id":8208,"date":"2021-02-01T07:40:20","date_gmt":"2021-02-01T06:40:20","guid":{"rendered":"https:\/\/www.maintenance-wordpress.online\/?p=8208"},"modified":"2021-02-01T13:47:22","modified_gmt":"2021-02-01T12:47:22","slug":"vulnerabilite-wordpress-plugins-janvier-2021","status":"publish","type":"post","link":"https:\/\/maintenance-cms-wp.fr\/articles\/vulnerabilite-wordpress-plugins-janvier-2021\/","title":{"rendered":"Vuln\u00e9rabilit\u00e9 WordPress Plugins Janvier 2021"},"content":{"rendered":"<h2>Derni\u00e8res failles de s\u00e9curit\u00e9 plugins et WordPress<\/h2>\n<p>Plusieurs nouvelles vuln\u00e9rabilit\u00e9s de plugins et de th\u00e8mes WordPress ont \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9es au cours de janvier 2021, nous voulons donc vous tenir au courant. Dans cet article, nous abordons les vuln\u00e9rabilit\u00e9s de plugins et de th\u00e8mes WordPress r\u00e9cents<\/p>\n<p>Il faut rapidement, \u00a0v\u00e9rifier les mises \u00e0 jour de ces plugins\/th\u00e8mes. <span style=\"color: #ff0000;\"><strong>Si aucune mise \u00e0 jour, vous devez les supprimer de votre installation WordPress !<\/strong><\/span>.<\/p>\n<p><b>WordPress Plugin Vulnerabilities<\/b><\/p>\n<ul>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/26819680-22a8-4348-b63d-dc52c0d50ed0\"><span style=\"color: #333333;\">Modern Events Calendar Lite &lt; 5.16.6 &#8211; Authenticated SQL Injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/f42cc26b-9aab-4824-8168-b5b8571d1610\"><span style=\"color: #333333;\">Modern Events Calendar Lite &lt; 5.16.5 &#8211; Authenticated Arbitrary File Upload leading to RCE<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/c7b1ebd6-3050-4725-9c87-0ea525f8fecc\"><span style=\"color: #333333;\">Modern Events Calendar Lite &lt; 5.16.5 &#8211; Unauthenticated Events Export<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/0f9ba284-5d7e-4092-8344-c68316b0146f\"><span style=\"color: #333333;\">Modern Events Calendar Lite &lt; 5.16.5 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/787aa6b0-82dc-4b6d-893b-a54fae43415f\"><span style=\"color: #333333;\">Super Forms &lt;= 4.9.602 &#8211; Unauthenticated PHP4 File Upload to RCE<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/f53b1c0f-43c5-4bc4-b5e7-e286c15f6f2e\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated Arbitrary Post\/Page Deletion<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/e52f7971-d8ef-49eb-8c2b-4b42d97fc9aa\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated SQL Injections<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/0db9774c-2c34-4a2c-988d-66ceccf27652\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated Arbitrary Roles and Capabilities Creation\/Deletion<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/68e509ed-dc3d-4070-8155-a5c02c682337\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated Information Disclosure<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/4e92a695-c3c1-4cc2-86d2-17e689ea9fca\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated WordPress Options Change<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/eb9fdc26-e382-46cc-966e-407ad93dc360\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated Arbitrary Account Change<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/3b946dcd-3224-4d40-89e1-ae039f0a9667\"><span style=\"color: #333333;\">uListing &lt; 1.7 &#8211; Unauthenticated Arbitrary Account Creation<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/143cdaff-c536-4ff9-8d64-c617511ddd48\"><span style=\"color: #333333;\">Contact Form 7 Database Addon &lt; 1.2.5.6 &#8211; CSV Injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/36afc442-9634-498e-961e-4c935880cd2b\"><span style=\"color: #333333;\">Doneren met Mollie &lt; 2.8.5 &#8211; Unauthorised CSV Export leading to Sensitive Data Disclosure<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/75f2eeb2-c413-4601-bc62-554683480c30\"><span style=\"color: #333333;\">Contact Form 7 Database Addon &lt; 1.2.5.4 &#8211; Authenticated SQL Injections<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/70ac3402-6ff7-48f5-b115-50e6b26f70de\"><span style=\"color: #333333;\">Digital Climate Strike WP &lt;= 1.0.0 &#8211; Redirect to Malicious Website due to Compromised JS Asset<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/2ec65510-5e4a-4af5-af58-3b0ca1b56c8d\"><span style=\"color: #333333;\">Under Construction &lt; 3.86 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/ee036303-0676-481a-98a4-76852fea6f62\"><span style=\"color: #333333;\">Stockdio Historical Chart &lt; 2.8.1 &#8211; Reflected Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/0b58b722-e75a-4dc2-b63b-35375f475344\"><span style=\"color: #333333;\">123ContactForm for WordPress &lt;= 1.5.6 &#8211; Unauthenticated Arbitrary File Upload<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/d3ef5644-1044-492f-ac23-ea90b32f1e77\"><span style=\"color: #333333;\">123ContactForm for WordPress &lt;= 1.5.6 &#8211; Unauthenticated Arbitrary Post Creation<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/ce716e4f-60f8-42e3-8891-a38e7948b970\"><span style=\"color: #333333;\">123ContactForm for WordPress &lt;= 1.5.6 &#8211; Validation Bypass via Plugin Verification<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/0e6b7a1f-dadd-45da-9961-6fe89ffb4c70\"><span style=\"color: #333333;\">e-signature &lt; 1.5.6.8 &#8211; Unauthenticated Arbitrary File Upload leading to RCE<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/8d0eb0b4-0cc0-44e5-b720-90b01df3a6ee\"><span style=\"color: #333333;\">WP Shieldon 1.6.3 &#8211; Unauthenticated Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/19800898-d7b6-4edd-887b-dac3c0597f14\"><span style=\"color: #333333;\">301 Redirects &#8211; Easy Redirect Manager &lt; 2.51 &#8211; Authenticated SQL Injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/eed3bd69-2faf-4bc9-915c-c36211ef9e2d\"><span style=\"color: #333333;\">Simple Job Board &lt; 2.9.4 &#8211; Authenticated Path Traversal Leading to Arbitrary File Download<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/86b26cde-2b98-4596-b0bc-02d65bd4f764\"><span style=\"color: #333333;\">FV Flowplayer Video Player &lt; 7.4.38.727 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/bfaa7d79-904e-45f1-bc42-ddd90a65ce74\"><span style=\"color: #333333;\">Easy Contact Form Pro &lt; 1.1.1.9 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/5ac30e5c-b2b9-4d15-a2ca-88d5ebdecc4e\"><span style=\"color: #333333;\">Elementor Contact Form DB &lt; 1.6 &#8211; Unauthenticated &amp; Unauthorised Form Submissions Export<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/b0943159-d164-4a5b-88bc-e0ada28beb32\"><span style=\"color: #333333;\">Elementor Contact Form DB &lt; 1.6 &#8211; Plugin Settings Cross-Site Request Forgery<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/d81d0e72-9bb5-47ef-a796-3b305a4b604f\"><span style=\"color: #333333;\">Orbit Fox by ThemeIsle &lt; 2.10.3 &#8211; Authenticated Privilege Escalation<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/28e42f4e-e38a-4bf4-b51b-d8f21c40f037\"><span style=\"color: #333333;\">Orbit Fox by ThemeIsle &lt; 2.10.3 &#8211; Authenticated Stored Cross Site Scripting<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/b4e6948f-ae4b-4256-ae93-7b0266785edd\"><span style=\"color: #333333;\">WP Quick FrontEnd Editor &lt;= 5.5 &#8211; Authenticated Settings Change leading to Stored XSS<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/21de3b4e-aa30-493b-993a-522f56da821e\"><span style=\"color: #333333;\">WP Quick FrontEnd Editor &lt;= 5.5 &#8211; Authenticated Content Injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/0480b2e3-5b3d-4eaf-9496-6a135f7cf4c9\"><span style=\"color: #333333;\">Custom Global Variables &lt;= 1.0.5 &#8211; Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/05dbd5a0-af45-40fa-a027-fc8f9dd9a706\"><span style=\"color: #333333;\">Modal Survey &lt; 2.0.1.8.2 &#8211; Authenticated PHP Object Injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/976c79e3-dd2c-4fb1-bbe2-5b3d7549b4b3\"><span style=\"color: #333333;\">Modal Survey &lt; 2.0.1.8.2 &#8211; Unauthenticated Arbitrary Survey Update, Deletion and Creation<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/1c21cf4e-d196-4edf-946e-70b78beaea01\"><span style=\"color: #333333;\">Modal Survey &lt; 2.0.1.8.2 &#8211; Authenticated Reflected Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/4c4075de-c6e0-4130-8cad-a4ea5311f5ea\"><span style=\"color: #333333;\">WP24 Domain Check &lt; 1.6.3 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/daa26c20-4295-40a3-b06f-62b22a635083\"><span style=\"color: #333333;\">Advanced Custom Fields &lt; 5.8.12 &#8211; Cross-Site Scripting in Select2 dropdowns<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/5c5f44e1-c00b-4a90-a581-ef06765b7f66\"><span style=\"color: #333333;\">Elementor &lt; 3.0.14 &#8211; SVG Upload Allowed by Default<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/e4136273-ffd5-4588-a47b-21a6105c1bca\"><span style=\"color: #333333;\">Stripe Payments &lt; 2.0.40 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/6df5f5b1-f10b-488e-80b3-2c024bbb8c78\"><span style=\"color: #333333;\">WP Paginate &lt; 2.1.4 &#8211; Authenticated Stored Cross-Site Scripting (XSS)<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/8591b3c9-b041-4ff5-b8d9-6f9f81041178\"><span style=\"color: #333333;\">Contact Form Submissions &lt;= 1.6.4 &#8211; Authenticated SQL Injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<li><a href=\"https:\/\/wpscan.com\/vulnerability\/0c3a91d4-a75a-4107-bfc5-015590a72abe\"><span style=\"color: #333333;\">Contact Form Submissions &lt;= 1.6.4 &#8211; Authenticated Double Query SQL injection<\/span><\/a><span style=\"color: #333333;\"><br \/>\n<\/span><\/li>\n<\/ul>\n<p><b>Ce qu\u2019il faut faire<\/b><\/p>\n<p><span style=\"color: #ff0000;\">Les vuln\u00e9rabilit\u00e9s n&rsquo;ont pas \u00e9t\u00e9 corrig\u00e9es. Gardez un \u0153il sur le journal des modifications pour une mise \u00e0 jour qui inclut un correctif.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h4 style=\"text-align: center;\">La maintenance de votre site WordPress permet des mises \u00e0 jour r\u00e9guli\u00e8res afin d\u2019\u00e9viter les bugs et les probl\u00e8mes de piratage.<\/h4>\n<p style=\"text-align: center;\"><a href=\"https:\/\/www.maintenance-cms-wp.fr\/services\/maintenance-et-support-wordpress\/\">Nous solutions de maintenance WordPress \u00e0 partir de 34\u20ac ht\/ mois\u00a0<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Derni\u00e8res failles de s\u00e9curit\u00e9 plugins et WordPress Plusieurs nouvelles vuln\u00e9rabilit\u00e9s de plugins et de th\u00e8mes WordPress ont \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9es au cours de janvier 2021, nous&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3343,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[31,32,30],"tags":[43,36,35],"class_list":["post-8208","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-plugins","category-vulnerabilite","category-wordpress","tag-securite","tag-vulnerabilite","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/posts\/8208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/comments?post=8208"}],"version-history":[{"count":0,"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/posts\/8208\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/media\/3343"}],"wp:attachment":[{"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/media?parent=8208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/categories?post=8208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/maintenance-cms-wp.fr\/articles\/wp-json\/wp\/v2\/tags?post=8208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}