4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-4751
WP Prayer II Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-13118
IP Based Login Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack

CVE-2024-6925
TrueBooker Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-10480
3DPrint Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-23493
Mattermost Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 

CVE-2024-1564
wp-schema-pro Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

CVE-2024-2908
Call Now Button Web Windows
4.3
MEDIUM
EPSS
2.5%
2024 1 PoC

The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9889
ElementInvader Addons for Elementor Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected posts, pages, and Elementor templates that they should not have access to.

CVE-2024-7984
Joy Of Text Lite Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-6860
WP MultiTasking Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-13580
XV Random Quotes Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2024-13208
Maps Plugin using Google Maps for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12436
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-8245
GamiPress Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-3410
DN Footer Contacts Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0623
VK Block Patterns Web Windows
4.3
MEDIUM
EPSS
4.1%
2024 CWE-352 1 PoC

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to missing or incorrect nonce validation on the vbp_clear_patterns_cache() function. This makes it possible for unauthenticated attackers to clear the patterns cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-3545
Server Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.

CVE-2024-4474
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
2.8%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-4969
Widget Bundle Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

CVE-2024-13306
Maps Plugin using Google Maps for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).