4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1011
AI ChatBot Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them.

CVE-2023-0236
Tutor LMS Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
20.1%
2023 1 PoC

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4603
Star CloudPRNT for WooCommerce Web Cloud Windows
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 2 PoCs

The Star CloudPRNT for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'printersettings' parameter in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-1377
Solidres Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-7170
EventON-RSVP Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1596
tagDiv Composer Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-7151
Product Enquiry for WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0769
hiWeb Migration Simple Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

CVE-2023-0479
Print Invoice & Delivery Notes for WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

CVE-2023-0043
Custom Add User Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Custom Add User WordPress plugin through 2.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2518
Easy Forms for Mailchimp Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0514
Membership Database Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
12.5%
2023 1 PoC

The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1835
Ninja Forms Contact Form Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2023 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-7230
illi Link Party! Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.

CVE-2023-6389
WordPress Toolbar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
52.5%
2023 1 PoC

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2023-0876
WP Meta SEO Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

CVE-2023-6050
Estatik Real Estate Plugin Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6627
WP Go Maps (formerly WP Google Maps) Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 2 PoCs

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.

CVE-2023-0644
Push Notifications for WordPress by PushAssist Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-6970
WP Recipe Maker Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.4%
2023 CWE-79 0 PoCs

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.