979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-28121
WooCommerce Payments WordPress Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2023 CWE-287 8 PoCs

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVE-2014-9119
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2014 2 PoCs

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2014-9444
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.

CVE-2014-4941
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2014 0 PoCs

Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php.

CVE-2015-4062
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.3%
2015 2 PoCs

SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2023-3139
Protect WP Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2023 1 PoC

The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

CVE-2015-9312
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2015 0 PoCs

The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.

CVE-2023-2256
Product Addons & Fields for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

CVE-2023-39026
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2023 2 PoCs

Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

CVE-2014-9094
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.2%
2014 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter.

CVE-2015-2755
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2015 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.

CVE-2023-3345
LMS by Masteriyo Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.8%
2023 1 PoC

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

CVE-2015-1000010
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.0%
2015 0 PoCs

Remote file download in simple-image-manipulator v1.0 wordpress plugin

CVE-2023-5974
wpb-show-core Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

CVE-2023-2309
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.2%
2023 1 PoC

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2014-4535
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.

CVE-2014-4558
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.

CVE-2015-4063
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2023-5991
Hotel Booking Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

CVE-2023-1893
Login Configurator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 2 PoCs

The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.