4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-36743
Product Catalog Simple Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to update product meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36755
Customizr Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the czr_fn_post_fields_save() function. This makes it possible for unauthenticated attackers to post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36742
Custom Field Template Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the edit_meta_value() function. This makes it possible for unauthenticated attackers to edit meta field values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36751
Coupon Creator Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_meta() function. This makes it possible for unauthenticated attackers to save meta fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36756
10WebAnalytics Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The 10WebAnalytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. This is due to missing or incorrect nonce validation on the create_csv_file() function. This makes it possible for unauthenticated attackers to create a CSV file via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36749
Easy Testimonials Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36757
WP Hotel Booking Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36737
Import / Export Customizer Settings Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the astra_admin_errors() function. This makes it possible for unauthenticated attackers to display an import status via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36750
EWWW Image Optimizer Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36735
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.3. This is due to missing or incorrect nonce validation on the handle_leave_calendar_filter, add_enable_disable_option_save, leave_policies, process_bulk_action, and process_crm_contact functions. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36746
Menu Swapper Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0.2. This is due to missing or incorrect nonce validation on the mswp_save_meta() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2018-10919
samba Windows
4.3
MEDIUM
EPSS
1.4%
2018 CWE-203 1 PoC

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

CVE-2018-13374
🔥 KEV Fortinet FortiOS, fortiADC Networking Windows
4.3
MEDIUM
EPSS
3.8%
2018 1 PoC

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVE-2010-3243
Software Genérico Web Windows
4.3
MEDIUM
EPSS
38.1%
2010 2 PoCs

Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."

CVE-2022-3451
Product Stock Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple AJAX actions, allowing users with a role as low as subscriber to call them. One action in particular could allow to update arbitrary options

CVE-2022-2913
Login No Captcha reCAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spoof IP addresses on the allow list and bypass the need for captcha on the login screen.

CVE-2022-4148
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.

CVE-2022-4549
Tickera Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2022-3126
Frontend File Manager Plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf

CVE-2022-3894
WP OAuth Server (OAuth Authentication) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.