4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-9939
Iptanus File Upload Web Windows
7.5
HIGH
EPSS
1.8%
2024 CWE-22 1 PoC

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.13 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read files outside of the originally intended directory.

CVE-2024-13478
LTL Freight Quotes – TForce Edition Web Database Windows
7.5
HIGH
EPSS
18.7%
2024 CWE-89 1 PoC

The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-12157
Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Web Database Windows
7.5
HIGH
EPSS
10.2%
2024 CWE-89 1 PoC

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action in all versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11728
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
65.9%
2024 CWE-89 1 PoC

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-49113
Windows 10 Version 1809 Windows
7.5
HIGH
EPSS
88.9%
2024 CWE-125 3 PoCs

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-13471
DesignThemes Core Features Web Windows
7.5
HIGH
EPSS
0.9%
2024 CWE-22 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.

CVE-2024-13488
LTL Freight Quotes – Estes Edition Web Database Windows
7.5
HIGH
EPSS
15.1%
2024 CWE-89 1 PoC

The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-4157
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Web Windows
7.5
HIGH
EPSS
0.5%
2024 CWE-502 1 PoC

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Successful exploitation

CVE-2024-13485
LTL Freight Quotes – ABF Freight Edition Web Database Windows
7.5
HIGH
EPSS
11.4%
2024 CWE-89 1 PoC

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-4565
Advanced Custom Fields (ACF) Web Windows
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

CVE-2024-12025
Collapsing Categories Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
80.6%
2024 CWE-89 1 PoC

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-12274
Appointment Booking Calendar Plugin and Scheduling Plugin Web Windows
7.5
HIGH
EPSS
0.5%
2024 1 PoC

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

CVE-2024-13322
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
21.5%
2024 CWE-89 0 PoCs

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-12812
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Windows
7.5
HIGH
EPSS
0.3%
2024 1 PoC

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.

CVE-2024-3475
Sticky Buttons Web Windows
7.5
HIGH
EPSS
0.1%
2024 1 PoC

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2024-12270
Beautiful taxonomy filters Web Database Windows
7.5
HIGH
EPSS
66.0%
2024 CWE-89 1 PoC

The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-10400
Tutor LMS – eLearning and online course solution Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
93.2%
2024 CWE-89 1 PoC

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-13926
WP-Syntax Web Windows
7.5
HIGH
EPSS
0.4%
2024 1 PoC

The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophic backtracking issue in the regular expression processing to cause a DoS.

CVE-2024-7315
Migration, Backup, Staging Web Windows
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.

CVE-2024-13925
Klarna Checkout for WooCommerce Web Windows
7.5
HIGH
EPSS
0.6%
2024 1 PoC

The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result in rapid consumption of disk space, potentially filling the entire disk.