4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1546
MyCryptoCheckout Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
29.2%
2023 1 PoC

The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-2488
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape various parameters before outputting them back in admin dashboard pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4460
Uploading SVG, WEBP and ICO files Web Windows
6.1
MEDIUM
EPSS
7.3%
2023 1 PoC

The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-3524
WPCode Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The WPCode WordPress plugin before 2.0.13.1 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-6621
POST SMTP Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-6161
WP Crowdfunding Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2303
Contact Form Builder by vcita Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.5. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1890
Tablesome Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.3%
2023 2 PoCs

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-3671
MultiParcels Shipping For WooCommerce Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6529
WP VR Web Windows
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, thus leading to Reflected or Stored XSS, as previous versions have such vulnerabilities.

CVE-2023-1806
WP Inventory Manager Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.

CVE-2023-2405
CRM and Lead Management by vcita Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This is due to missing nonce validation in the vcita-callback.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-2438
UserPro - Community and User Profile WordPress Plugin Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'userpro_save_userdata' function. This makes it possible for unauthenticated attackers to update the user meta and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-2337
ConvertKit Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-5955
Contact Form Email Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4687
Page Builder: Pagelayer Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.

CVE-2023-4476
Locatoraid Store Locator Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-3320
WP Sticky Social Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 1 PoC

The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0899
Steveas WP Live Chat Shoutbox Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2023-0187
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service.