979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-2518
Easy Forms for Mailchimp Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.6%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-0514
Membership Database Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
12.5%
2023 1 PoC

The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13112
WP MediaTagger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.5%
2024 1 PoC

The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-1835
Ninja Forms Contact Form Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
14.2%
2023 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.22 does not properly escape user input before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0948
Japanized For WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
22.9%
2023 1 PoC

The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-6389
WordPress Toolbar Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
52.5%
2023 1 PoC

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2025-62522
vite Web Windows ⚡ nuclei
6.0
MEDIUM
EPSS
0.9%
2025 CWE-22 0 PoCs

Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.

CVE-2024-9796
WP-Advanced-Search Web Database Windows ⚡ nuclei
5.9
MEDIUM
EPSS
83.1%
2024 5 PoCs

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2024-3753
Hostel Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
1.5%
2024 1 PoC

The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13609
1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
17.7%
2024 CWE-200 0 PoCs

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.

CVE-2022-3590
WordPress Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
90.8%
2022 4 PoCs

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

CVE-2019-19985
Software Genérico Web Windows ⚡ nuclei
5.8
MEDIUM
EPSS
79.6%
2019 2 PoCs

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

CVE-2026-0829
Frontend File Manager Plugin Web Windows ⚡ nuclei
5.8
MEDIUM
EPSS
2.6%
2026 1 PoC

The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded files without permission, exposing sensitive information.

CVE-2021-36873
iQ Block Country Web Windows ⚡ nuclei
5.5
MEDIUM
EPSS
1.8%
2021 CWE-79 0 PoCs

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

CVE-2022-3934
FlatPM Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
4.9%
2022 1 PoC

The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-7246
System Dashboard Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
1.5%
2023 1 PoC

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

CVE-2024-13097
WP Finance Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-28665
Woo Bulk Price Update WordPress Plugin Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
21.8%
2023 1 PoC

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

CVE-2024-13098
WordPress Email Newsletter Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.1%
2024 1 PoC

The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-2745
WordPress Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
77.2%
2023 CWE-22 2 PoCs

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.