4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-10684
Construction Light Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVE-2025-5526
BuddyPress Docs Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user

CVE-2025-12971
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

CVE-2025-9888
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-8891
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-0748
Homey Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the 'homey_verify_user_manually' function. This makes it possible for unauthenticated attackers to update verify an user via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-15473
Timetics Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

CVE-2025-4580
File Provider Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-12189
Bread & Butter: AI-Powered Lead Intelligence Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 2 PoCs

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-13794
Auto Featured Image (Auto Post Thumbnail) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete or generate featured images on posts they do not own.

CVE-2025-1362
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

CVE-2025-5730
Contact Form Plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2025-8595
Zakra Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

CVE-2025-10700
Ally – Web Accessibility & Usability Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-8682
Newsup Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

CVE-2025-9202
ColorMag Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.

CVE-2025-7965
CBX Restaurant Booking Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-9979
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

CVE-2025-9703
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

CVE-2025-11587
Call Now Button – The #1 Click to Call Button for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to link the plugin to their nowbuttons.com account and add malicious buttons to the site. The vulnerability is only exploitable on fresh installs where the plugin has not been previously configured with an API key.