4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6910
EventON Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-6094
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12567
Email Subscribers by Icegram Express Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13482
Icegram Engage Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6617
NinjaTeam Header Footer Custom Code Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12770
WP ULike Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-1958
wpb-show-core Web Windows
4.8
MEDIUM
EPSS
1.1%
2024 1 PoC

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

CVE-2024-6335
Tracking Code Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Tracking Code Manager WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-7918
Pocket Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11221
Full Screen (Page) Background Image Slideshow Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5029
CM Table Of Contents Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-3635
The Post Grid Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as Editor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13730
Podlove Podcast Publisher Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9227
PowerPress Podcasting plugin by Blubrry Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2024-9638
Category Posts Widget Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12739
Mobile Contact Bar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7052
Forminator Forms Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8701
events-calendar Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13621
The GDPR Framework By Data443 Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6270
Community Events Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)