4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4658
RSSImport Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4835
Social Sharing Toolkit Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3935
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks

CVE-2022-4826
Simple Tooltips Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4578
Video Conferencing with Zoom Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4622
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4834
CPT Bootstrap Carousel Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4391
Vision Interactive For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-4795
Galleries by Angie Makes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Galleries by Angie Makes WordPress plugin through 1.67 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4464
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.

CVE-2022-4824
WP Blog and Widgets Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3987
Responsive Lightbox2 Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4825
WP-ShowHide Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-ShowHide WordPress plugin before 1.05 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-2413
Slide Anything Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.

CVE-2022-4491
WP-Table Reloaded Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-4005
Donation Button Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-4678
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-3986
WP Stripe Checkout Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4718
Landing Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4483
Insert Pages Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Insert Pages WordPress plugin before 3.7.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.