4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-11842
DN Shipping by Weight for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12709
Bulk Me Now! Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-12750
Competition Form Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-10634
Nokaut Offers Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack

CVE-2024-5169
Video Widget Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10677
BTEV Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1319
Events Tickets Plus Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).

CVE-2024-12280
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack

CVE-2024-1279
Paid Memberships Pro Web Windows
4.3
MEDIUM
EPSS
0.5%
2024 1 PoC

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

CVE-2024-2429
Salon booking system Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-9926
Jetpack Web Windows
4.3
MEDIUM
EPSS
22.8%
2024 1 PoC

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

CVE-2024-34029
Mattermost Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.

CVE-2024-8009
Sensei LMS Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

CVE-2024-3477
Popup Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks

CVE-2024-1745
Testimonial Slider Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them.

CVE-2024-2744
NextGEN Gallery Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-9233
Logo Slider Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-0248
EazyDocs Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 2 PoCs

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

CVE-2024-4475
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack

CVE-2024-0379
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Web Windows
4.3
MEDIUM
EPSS
13.9%
2024 CWE-352 1 PoC

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.