979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-4151
Store Locator WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2023 1 PoC

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0334
ShortPixel Adaptive Images Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.1%
2023 1 PoC

The ShortPixel Adaptive Images WordPress plugin before 3.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against any high privilege users such as admin

CVE-2023-6697
WP Go Maps (formerly WP Google Maps) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
54.2%
2023 CWE-79 0 PoCs

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-0942
Japanized for WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
39.9%
2023 CWE-79 0 PoCs

The Japanized For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 2.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-4148
Ditty Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
9.9%
2023 1 PoC

The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-1119
WP-Optimize Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
24.2%
2023 1 PoC

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.

CVE-2023-5558
LearnPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.6%
2023 1 PoC

The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0448
WP Helper Lite Wordpress Plugin Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
27.7%
2023 1 PoC

The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.

CVE-2023-0236
Tutor LMS Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
20.1%
2023 1 PoC

The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2518
Easy Forms for Mailchimp Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0514
Membership Database Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
12.5%
2023 1 PoC

The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1835
Ninja Forms Contact Form Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2023 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-6389
WordPress Toolbar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
52.5%
2023 1 PoC

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2023-0876
WP Meta SEO Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

CVE-2023-6970
WP Recipe Maker Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
16.4%
2023 CWE-79 0 PoCs

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2023-1546
MyCryptoCheckout Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
29.2%
2023 1 PoC

The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-1890
Tablesome Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
8.3%
2023 2 PoCs

The Tablesome WordPress plugin before 1.0.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-6786
Payment Gateway for Telcell Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2023-3169
tagDiv Composer Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
36.1%
2023 1 PoC

The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

CVE-2023-0968
Watu Quiz Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.0%
2023 CWE-79 0 PoCs

The Watu Quiz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dn’, 'email', 'points', and 'date' parameters in versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.