4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-0604
WP Food Manager Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Food Manager WordPress plugin before 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0059
Youzify Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1861
Limit Login Attempts Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks

CVE-2023-4783
Magee Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0526
Post Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0170
Html5 Audio Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0492
GS Products Slider for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0154
GamiPress Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0082
ExactMetrics Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0034
JetWidgets For Elementor Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4820
PowerPress Podcasting plugin by Blubrry Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

CVE-2023-2899
Google Map Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2023-0147
Flexible Captcha Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-1069
Complianz Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2334
edd-google-sheet-connector-pro Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-6030
LogDash Activity Log Web Database Windows ⚡ nuclei
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker

CVE-2023-0078
Resume Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

CVE-2023-0176
Giveaways and Contests by RafflePress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4821
Drag and Drop Multiple File Upload for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

CVE-2023-0536
Wp-D3 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.