4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1614
WP Custom Author URL Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-7115
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-3499
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6037
WP TripAdvisor Review Slider Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-7154
Hubbub Lite (formerly Grow Social) Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5137
Simply Excerpts Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simply Excerpts WordPress plugin through 1.4 does not sanitize and escape some fields in the plugin settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVE-2023-6163
WP Crowdfunding Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0157
All-In-One Security (AIOS) Web Windows
4.8
MEDIUM
EPSS
25.1%
2023 2 PoCs

The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not escape the content of log files before outputting it to the plugin admin page, allowing an authorized user (admin+) to plant bogus log files containing malicious JavaScript code that will be executed in the context of any administrator visiting this page.

CVE-2023-5943
Wp-Adv-Quiz Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2023-2995
Leyka Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Leyka WordPress plugin before 3.30.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2684
File Renaming on Upload Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0420
Custom Post Type and Taxonomy GUI Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF

CVE-2023-2113
Autoptimize Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.

CVE-2023-3245
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0894
Pickup | Delivery | Dine-in date time Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4060
WP Adminify Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Adminify WordPress plugin before 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1120
Simple Giveaways Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5932
Travelpayouts: All Travel Brands in One Place Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2527
Integration for Contact Form 7 and Zoho CRM, Bigin Web Database Windows
4.8
MEDIUM
EPSS
0.1%
2023 2 PoCs

The Integration for Contact Form 7 and Zoho CRM, Bigin WordPress plugin before 1.2.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-3501
FormCraft Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).