4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-6859
WP MultiTasking Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-4270
SVGMagic Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-13097
WP Finance Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-3633
WebP & SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-10473
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2024-5417
Gutentor Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-4005
Social Pixel Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9879
Melapress File Monitor Web Database Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-11841
Tithe.ly Giving Button Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-2404
Better Comments Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.

CVE-2024-7353
Accept Stripe Payments Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 CWE-79 1 PoC

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-7690
DN Popup Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-9709
EKC Tournament Manager Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1487
Photos and Files Contest Gallery Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.

CVE-2024-11718
tarteaucitron-wp Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-1306
Smart Forms Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.

CVE-2024-13098
WordPress Email Newsletter Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.1%
2024 1 PoC

The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-2470
Simple Ajax Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5627
Tournamatch Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.