11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-7688
AZIndex Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack

CVE-2022-3926
WP OAuth Server (OAuth Authentication) Web Windows
6.5
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID

CVE-2025-13922
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied parameters and lack of SQL query parameterization. This makes it possible for authenticated attackers, with Contributor-level access and above who have AI metabox permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information

CVE-2024-6133
wp-cart-for-digital-products Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-1287
pmpro-member-directory Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

CVE-2024-1290
User Registration Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts.

CVE-2024-6856
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-10631
Countdown Timer for WordPress Block Editor Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-3880
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan Web Windows
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4.20 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org

CVE-2021-36917
Hide My WP (WordPress plugin) Web Windows
6.5
MEDIUM
EPSS
1.2%
2021 CWE-284 1 PoC

WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.

CVE-2024-5028
CM WordPress Search And Replace Plugin Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2024-6490
Master Slider Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

CVE-2022-4151
Contest Gallery Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.

CVE-2024-5522
HTML5 Video Player Web Database Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.8%
2024 6 PoCs

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2021-43408
Duplicate Post WordPress Plugin Web Database Windows
6.5
MEDIUM
EPSS
30.6%
2021 CWE-89 1 PoC

The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrat

CVE-2021-24085
Microsoft Exchange Server 2019 Cumulative Update 8 Windows
6.5
MEDIUM
EPSS
13.2%
2021 1 PoC

Microsoft Exchange Server Spoofing Vulnerability

CVE-2024-57972
HoloLens Web Windows
6.5
MEDIUM
EPSS
1.9%
2024 CWE-770 1 PoC

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.

CVE-2022-30312
Software Genérico Windows
6.5
MEDIUM
EPSS
0.0%
2022 1 PoC

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in or

CVE-2022-4236
Welcart e-Commerce Web Windows
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server.