4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-0282
YourChannel: Everything you want in a YouTube plugin. Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

CVE-2023-0150
Cloak Front End Email Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4757
Staff / Employee Business Directory for Active Directory Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVE-2023-6530
TJ Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-7246
System Dashboard Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
1.5%
2023 1 PoC

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

CVE-2023-0272
NEX-Forms Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0070
ResponsiveVoice Text To Speech Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0540
GS Filterable Portfolio Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0546
Contact Form Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins previewing or editing the form.

CVE-2023-0370
WPB Advanced FAQ Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-28665
Woo Bulk Price Update WordPress Plugin Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
21.8%
2023 1 PoC

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

CVE-2023-0069
WPaudio MP3 Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0151
uTubeVideo Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4289
WP Matterport Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0153
Vimeo Video Autoplay Automute Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Vimeo Video Autoplay Automute WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4795
Testimonial Slider Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2023-0376
Qubely Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-7084
Voting Record Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks

CVE-2023-0275
Easy Accept Payments for PayPal Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2745
WordPress Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
77.2%
2023 CWE-22 2 PoCs

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.