4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-2405
WP Popup Builder – Popup Forms , Marketing PoPuP & Newsletter Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

CVE-2022-4103
Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title

CVE-2022-4426
Mautic Integration for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack.

CVE-2022-2387
Easy Digital Downloads – Simple eCommerce for Selling Digital Files Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-352 1 PoC

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

CVE-2022-3994
Authenticator Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations.

CVE-2022-3151
WP Custom Cursors Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-352 1 PoC

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could allow attackers to made a logged in admin delete arbitrary cursors via a CSRF attack.

CVE-2022-2912
Craw Data Web Windows
4.3
MEDIUM
EPSS
0.4%
2022 CWE-918 1 PoC

The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logged in admin change the url value performing unwanted crawls on third-party sites (SSRF).

CVE-2022-3282
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit set in forms, taking the value from user input sent when submitting the form. As a result, attackers could control the file length limit and bypass the limit set by admins in the contact form.

CVE-2022-2460
WPDating Web Database Windows
4.3
MEDIUM
EPSS
4.4%
2022 1 PoC

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

CVE-2022-4872
Chained Products Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'

CVE-2022-4004
Donation Button Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

CVE-2022-23180
Contact Form & Lead Form Elementor Builder Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

CVE-2022-3923
ActiveCampaign for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

CVE-2022-4553
FL3R FeelBox Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables

CVE-2022-4124
Popup Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them

CVE-2022-3995
Wallet for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to lock/unlock other users wallets.

CVE-2022-0775
WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which could allow any authenticated users, such as subscriber to delete arbitrary comment

CVE-2022-3850
Find and Replace All Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack

CVE-2022-2846
Calendar Event Multi View Web Windows
4.3
MEDIUM
EPSS
3.0%
2022 CWE-862 2 PoCs

The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.

CVE-2022-2450
reSmush.it : the only free Image Optimizer & compress plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them.