4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13222
User Messages Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.6%
2024 1 PoC

The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-4269
SVG Block Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-7861
Misiek Paypal Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-13221
Fantastic ElasticSearch Web Database Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12731
Aklamator INfeed Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0673
Pz-LinkCard Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-10703
Registrations for the Events Calendar Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12723
Infility Global Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-9934
Wp-ImageZoom Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-8386
Firefox Windows
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVE-2024-13225
ECT Home Page Products Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.2%
2024 1 PoC

The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-3917
Pet Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12586
Chalet-Montagne.com Tools Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6334
Easy Table of Contents Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-0239
Contact Form 7 Connector Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.

CVE-2024-6651
WordPress File Upload Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
18.5%
2024 1 PoC

The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-8056
MM-Breaking News Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-13112
WP MediaTagger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-8054
MM-Breaking News Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-4149
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).