2297 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-13749
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attackers to disable plugin/theme update notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-47871
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2025 CWE-863 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint.

CVE-2025-12971
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

CVE-2025-11762
HubSpot All-In-One Marketing – Forms, Popups, Live Chat Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract a list of all installed plugins and their versions which can be leveraged for reconnaissance and further attacks.

CVE-2025-46550
yeswiki Web ⚡ nuclei
4.3
MEDIUM
EPSS
0.4%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.

CVE-2025-11369
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with Author-level access and above, to view API keys configured for the external services.

CVE-2025-11587
Call Now Button – The #1 Click to Call Button for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to link the plugin to their nowbuttons.com account and add malicious buttons to the site. The vulnerability is only exploitable on fresh installs where the plugin has not been previously configured with an API key.

CVE-2025-9703
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

CVE-2025-8669
Customify Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing or incorrect nonce validation on the reset_customize_section function. This makes it possible for unauthenticated attackers to reset theme customization settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-13753
WP Table Builder – Drag & Drop Table Builder Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

CVE-2025-8383
Depicter — Popup & Slider Builder Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-6790
Quiz and Survey Master (QSM) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2025-27454
Endress+Hauser MEAC300-FNADE4 Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-352 1 PoC

The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did not intend. The request uses the victim's browser's saved authorization to execute the request.

CVE-2025-12559
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

CVE-2025-9888
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-8891
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-0748
Homey Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the 'homey_verify_user_manually' function. This makes it possible for unauthenticated attackers to update verify an user via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-60134
WP Media Categories Web
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Media Categories wp-media-categories allows Cross Site Request Forgery.This issue affects WP Media Categories: from n/a through <= 2.1.0.

CVE-2025-12494
Modula Image Gallery – Photo Grid & Video Gallery Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above, to move arbitrary image files on the server.

CVE-2025-58055
discourse Web
4.3
MEDIUM
EPSS
0.1%
2025 CWE-284 2 PoCs

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about topics that they weren’t authorized to access. By modifying the “topic_id” value in API requests to the AI suggestion endpoints, users could target specific restricted topics. The AI model’s responses then disclosed information that the authenticated user couldn’t normally access. This issue is fixed in version 3.5.1. To workaround this issue, users can restrict group acce