4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-4388
Opal Estate Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-862 1 PoC

The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties.

CVE-2021-4387
Opal Estate Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4400
Better Search – Relevant search results for WordPress Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the bsearch_process_settings_import() and bsearch_process_settings_export() functions. This makes it possible for unauthenticated attackers to import and export settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4390
Contact Form 7 Style Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated attackers to quick edit templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4423
RAYS Grid Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the rsgd_insert_update() function. This makes it possible for unauthenticated attackers to update post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-27594
SAP 3D Visual Enterprise Viewer Windows
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2021-4396
Rucy Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Rucy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.4. This is due to missing or incorrect nonce validation on the save_rc_post_meta() function. This makes it possible for unauthenticated attackers to save post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4405
ElasticPress Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on the epio_send_autosuggest_allowed() function. This makes it possible for unauthenticated attackers to send allowed parameters for autosuggest to elasticpress[.]io via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4415
Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.28 This is due to missing or incorrect nonce validation on the sunshine_products_quicksave_post() function. This makes it possible for unauthenticated attackers to save custom post data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4409
Etsy Integration For WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.1. This is due to missing or incorrect nonce validation on the etcpf_delete_feed() function. This makes it possible for unauthenticated attackers to delete an export feed via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4412
WP Prayer Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the save() and export() functions. This makes it possible for unauthenticated attackers to save plugin settings and trigger a data export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4399
Edwiser Bridge – WordPress Moodle Integration Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(), connection_test_initiater(), admin_menus(), and subscribe_handler() function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4413
Process Steps Template Designer Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4392
eCommerce Product Catalog Plugin for WordPress Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save product meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4386
WP Security Question Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4419
WP-Backgrounds Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the ino_save_data() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4403
Remove Schema Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4422
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Web Windows
4.3
MEDIUM
EPSS
0.3%
2021 CWE-352 7 PoCs

The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4425
Defender Security – Malware Scanner, Login Security & Firewall Web Networking Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Defender Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the verify_otp_login_time() function. This makes it possible for unauthenticated attackers to verify a one time login via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4414
Abandoned Cart Lite for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it possible for unauthenticated attackers to generate email preview templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.