4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-6905
NxFilter Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-90 1 PoC

A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler. The manipulation leads to ldap injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-248267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5772
Debug Log Manager – Conveniently Monitor and Inspect Errors Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1414
WP VR Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours

CVE-2023-0763
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack

CVE-2023-0495
HT Slider For Elementor Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6066
WP Custom Widget area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.

CVE-2023-1087
WC Sales Notification Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-4059
Profile Builder Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

CVE-2023-6385
WordPress Ping Optimizer Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.

CVE-2023-6843
easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress plugin before 2.4.7 does not properly secure some of its AJAX actions, allowing any logged-in users to modify its settings.

CVE-2023-7195
WP-Reply Notify Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2023-0467
WP Dark Mode Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory creation.

CVE-2023-3178
POST SMTP Mailer Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.

CVE-2023-5713
System Dashboard Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.

CVE-2023-0496
HT Event Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0503
Free WooCommerce Theme 99fy Extension Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-0453
WP Private Message Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVE-2023-5531
Thumbnail Slider With Lightbox Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-6289
Swift Performance Lite Web Cloud Windows
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

CVE-2023-0498
WP Education Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack