4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4545
Sitemap Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4668
Easy Appointments Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4674
Ibtana Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack

CVE-2022-4666
Markup (JSON-LD) structured in schema.org Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4781
Accordion Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4837
CPO Companion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4624
GS Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4652
Video Background Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4750
WP Responsive Testimonials Slider And Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4838
Clean Login Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4790
WP Google My Business Auto Publish Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4576
Easy Bootstrap Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3025
Bitcoin / Altcoin Faucet Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2022-4648
Real Testimonials Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3983
Checkout for PayPal Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4473
Widget Shortcode Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4477
Smash Balloon Social Post Feed Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.6 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4577
Easy Testimonials Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4760
OneClick Chat to Order Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-44875
Software Genérico Web Windows
5.4
MEDIUM
EPSS
1.7%
2022 2 PoCs

KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.