4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-4390
Popup box Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVE-2023-3667
Chat Button: WhatsApp Chat, Facebook Messenger, Telegram Chat, WeChat, Line Chat, Discord Chat for Customer Support Chat with floating Chat Widget Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5181
WP Discord Invite Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0874
Klaviyo Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Klaviyo WordPress plugin before 3.0.10 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2707
gAppointments Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1649
AI ChatBot Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-3721
WP-EMail Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4858
Simple Table Manager Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Table Manager WordPress plugin through 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-3897
SureMDM Onpremise Windows
4.8
MEDIUM
EPSS
1.3%
2023 CWE-203 2 PoCs

Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error message. This issue affects SureMDM On-premise: 6.31 and below version

CVE-2023-3170
tagDiv Composer Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0548
Namaste! LMS Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-3248
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4109
Ninja Forms Contact Form Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by a HTML Injection security vulnerability.

CVE-2023-4810
Responsive Pricing Table Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 2 PoCs

The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1839
Product Addons & Fields for WooCommerce Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.6 does not sanitize and escape some of its setting fields, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-4725
Simple Posts Ticker Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Posts Ticker WordPress plugin before 1.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6591
Popup Box Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-0544
WP Login Box Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4925
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-2009
Pretty Url Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
3.0%
2023 1 PoC

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).