979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24210
PhastPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.4%
2021 CWE-601 2 PoCs

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.

CVE-2021-24145
Modern Events Calendar Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 CWE-434 4 PoCs

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

CVE-2014-5181
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2014 0 PoCs

Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snode parameter.

CVE-2013-7240
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
41.5%
2013 2 PoCs

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

CVE-2023-2813
Aapna Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop

CVE-2021-24522
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

CVE-2021-24875
eCommerce Product Catalog Plugin for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2021 CWE-79 1 PoC

The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24170
User Profile Picture Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.1%
2021 CWE-200 1 PoC

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVE-2021-24452
W3 Total Cache Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

CVE-2021-24762
Perfect Survey Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2021 CWE-89 3 PoCs

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

CVE-2015-9406
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2015 2 PoCs

Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.

CVE-2021-24347
SP Project & Document Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.6%
2021 CWE-178 4 PoCs

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

CVE-2021-24498
Calendar Event Multi View Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.5%
2021 CWE-79 1 PoC

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

CVE-2021-24876
Registrations for the Events Calendar – Event Registration Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2013-4625
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.2%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

CVE-2015-9415
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
18.0%
2015 1 PoC

The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

CVE-2021-29156
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.7%
2021 2 PoCs

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.

CVE-2021-24236
Imagements Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.1%
2021 CWE-434 1 PoC

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

CVE-2021-25052
Button Generator – easily Button Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.4%
2021 CWE-352 1 PoC

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

CVE-2021-24947
RVM – Responsive Vector Maps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2021 CWE-863 1 PoC

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server