4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-0505
Ever Compare Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1939
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.

CVE-2023-0761
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack

CVE-2023-6625
Product Enquiry for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2023-1089
Coupon Zen Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-4150
User Activity Tracking and Log Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

CVE-2023-0497
HT Portfolio Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-3366
MultiParcels Shipping For WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

CVE-2023-4251
EventPrime Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.

CVE-2023-4023
All Users Messenger Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger.

CVE-2023-0499
QuickSwish Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2024-9756
Order Attachments for WooCommerce Web Windows
4.3
MEDIUM
EPSS
4.1%
2024 CWE-862 1 PoC

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

CVE-2024-8082
Widgets Reset Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-11672
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

CVE-2024-4382
CB (legacy) Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

CVE-2024-1330
kadence-blocks-pro Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

CVE-2024-7862
blogintroduction-wordpress-plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-3163
Easy Property Listings Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-9583
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-862 1 PoC

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.

CVE-2024-8157
Alphabetical List Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack