4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13678
R3W InstaFeed Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-0238
EventON Premium Web Windows
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that the post to be updated belong to the plugin, allowing unauthenticated users to update arbitrary post metadata.

CVE-2024-5448
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-3641
Newsletter Popup Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins

CVE-2024-5081
wp-eMember Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-8085
PeoplePond Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-8032
Smooth Gallery Replacement Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-6020
Sign-up Sheets Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.

CVE-2024-13492
Guten Free Options Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2024 1 PoC

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-13327
Musicbox Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-2278
Themify Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4384
CSSable Countdown Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1589
SendPress Newsletters Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0233
EventON Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-4289
Sailthru Triggermail Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12715
Asgard Security Scanner Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6017
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-4272
Support SVG Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-5155
Inquiry cart Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13825
Email Keep Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.