4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2779
Social Share, Social Login and Social Comments Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
30.8%
2023 3 PoCs

The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-2301
Contact Form Builder by vcita Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 CWE-352 1 PoC

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.3. This is due to missing nonce validation on the ls_parse_vcita_callback function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. While the Cross-Site Scripting issue was patched in version 4.10.1, the plugin is still technically vulnerable to Cross-Site Request Forgery s

CVE-2023-2572
Survey Maker Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Survey Maker WordPress plugin before 3.4.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0733
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.6%
2023 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

CVE-2023-7167
Persian Fonts Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-4602
Namaste! LMS Web Windows
6.1
MEDIUM
EPSS
0.8%
2023 CWE-79 1 PoC

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-1282
Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.

CVE-2023-1324
Easy Forms for Mailchimp Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1465
WP EasyPay Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP EasyPay WordPress plugin before 4.1 does not escape some generated URLs before outputting them back in pages, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin

CVE-2024-11719
tarteaucitron-wp Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-1273
Starbox Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

CVE-2024-6289
WPS Hide Login Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
7.3%
2024 1 PoC

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

CVE-2024-4534
KKProgressbar2 Free Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-2189
Social Icons Widget & Block by WPZOOM Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12290
Infility Global Web Windows
6.1
MEDIUM
EPSS
2.0%
2024 CWE-79 1 PoC

The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE-2024-12723 is a duplicate of this issue.

CVE-2024-1331
Team Members Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 1 PoC

The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5809
WP Ajax Contact Form Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users

CVE-2024-13853
SEO Tools Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.9%
2024 1 PoC

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-7761
Simple Job Board Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

CVE-2024-5199
Spotify Play Button Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.