4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-3965
Pray For Me Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-6754
Social Auto Poster Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post metadata.

CVE-2024-10482
Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-5074
wp-eMember Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-11670
Remote Desktop Manager Windows
5.4
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.

CVE-2024-0757
Insert or Embed Articulate Content into WordPress Web Windows
5.4
MEDIUM
EPSS
59.1%
2024 2 PoCs

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

CVE-2024-3971
Similarity Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2024-10563
WooCommerce Cart Count Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-8239
Starbox Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.

CVE-2024-9599
Popup Box Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10980
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-9662
CYAN Backup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9838
Auto Affiliate Links Web Database Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Auto Affiliate Links WordPress plugin before 6.4.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-1849
WP Customer Reviews Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL

CVE-2024-9711
EKC Tournament Manager Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-2837
WP Chat App Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-9020
List category posts Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3058
ENL Newsletter Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-1846
Responsive Tabs Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-4483
Email Encoder Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting