979 vulnerabilidades · Windows · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24862
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 CWE-89 2 PoCs

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVE-2021-24165
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-601 1 PoC

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

CVE-2023-0630
Slimstat Analytics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2023 2 PoCs

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

CVE-2022-1221
Gwyn's Imagemap Selector Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-79 1 PoC

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

CVE-2013-7091
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2013 2 PoCs

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

CVE-2015-1000012
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.6%
2015 0 PoCs

Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin

CVE-2021-25082
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.7%
2021 CWE-22 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CVE-2021-25032
PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2021 CWE-352 2 PoCs

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

CVE-2015-4127
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

CVE-2021-24220
Rise by Thrive Themes Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
63.8%
2021 CWE-434 2 PoCs

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using th

CVE-2021-24407
Jannah Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-79 1 PoC

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

CVE-2023-2272
Tiempo.com Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-25028
Event Tickets Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2021 CWE-601 1 PoC

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

CVE-2021-25118
Yoast SEO Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.3%
2021 CWE-200 1 PoC

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

CVE-2021-24227
Patreon WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
38.7%
2021 CWE-200 0 PoCs

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

CVE-2021-25120
Easy Social Feed Pro Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.6%
2021 CWE-79 1 PoC

The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues

CVE-2021-24910
Transposh WordPress Translation Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.6%
2021 CWE-79 1 PoC

The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJAX action (available to both unauthenticated and authenticated users when the curl library is installed) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24175
The Plus Addons for Elementor Page Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2021 CWE-287 2 PoCs

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

CVE-2021-24287
Select All Categories and Taxonomies, Change Checkbox to Radio Buttons Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
22.3%
2021 CWE-79 2 PoCs

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

CVE-2021-24284
Kaswara Modern VC Addons Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.0%
2021 CWE-434 2 PoCs

The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.