4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-7236
Backup Bolt Web Windows
4.7
MEDIUM
EPSS
0.4%
2023 1 PoC

The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.

CVE-2023-1112
Drag and Drop Multiple File Upload Contact Form 7 Web Windows
4.7
MEDIUM
EPSS
31.8%
2023 CWE-23 1 PoC

A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222072.

CVE-2023-32019
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
2.8%
2023 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2024-6073
wp-cart-for-digital-products Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-2159
Social Sharing Plugin Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5575
Ditty Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-5727
Widget4Call Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-1754
NPS computy Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4217
shortcodes-ultimate-pro Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

CVE-2024-1292
wpb-show-core Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-10903
Broken Link Checker Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.

CVE-2024-8968
WordPress Button Plugin MaxButtons Web Windows
4.7
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11223
WPForms Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5280
wp-affiliate-platform Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

CVE-2024-2262
Themify Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

CVE-2024-3754
Alemha watermarker Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6879
Quiz and Survey Master (QSM) Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.

CVE-2024-1712
Carousel Slider Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3941
reCAPTCHA Jetpack Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-7689
Snapshot Backup Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.