11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1371
W4 Post List Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

CVE-2021-43408
Duplicate Post WordPress Plugin Web Database Windows
6.5
MEDIUM
EPSS
30.6%
2021 CWE-89 1 PoC

The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also possible to exploit features of SQL server to execute system commands and/or access the local file system. This particular vulnerability can be exploited by any authenticated user who has been granted access to use the Duplicate Post plugin. By default, this is limited to Administrat

CVE-2021-4377
Doneren met Mollie Web Windows
6.5
MEDIUM
EPSS
0.4%
2021 CWE-200 1 PoC

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVE-2025-8994
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from th

CVE-2024-2843
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin users delete users via CSRF attacks

CVE-2021-24085
Microsoft Exchange Server 2019 Cumulative Update 8 Windows
6.5
MEDIUM
EPSS
13.2%
2021 1 PoC

Microsoft Exchange Server Spoofing Vulnerability

CVE-2024-3591
Geo Controller Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2025-12685
WPBookit Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack.

CVE-2024-6755
Social Auto Poster Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to delete arbitrary posts.

CVE-2024-9765
EKC Tournament Manager Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
4.6%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

CVE-2023-5070
Social Media Share Buttons & Social Sharing Icons Web Windows
6.5
MEDIUM
EPSS
14.9%
2023 CWE-200 1 PoC

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.

CVE-2024-43335
Responsive Blocks – WordPress Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks – WordPress Gutenberg Blocks allows Stored XSS.This issue affects Responsive Blocks – WordPress Gutenberg Blocks: from n/a through 1.8.8.

CVE-2018-16851
samba Windows
6.5
MEDIUM
EPSS
9.2%
2018 CWE-476 1 PoC

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service.

CVE-2025-13922
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2025 CWE-89 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied parameters and lack of SQL query parameterization. This makes it possible for authenticated attackers, with Contributor-level access and above who have AI metabox permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information

CVE-2024-6490
Master Slider Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an unauthorized user to manipulate requests on behalf of the victim and thereby delete all of the sliders inside Master Slider WordPress plugin through 3.9.10.

CVE-2025-55311
Software Genérico Web Windows
6.5
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

CVE-2018-14629
samba Windows
6.5
MEDIUM
EPSS
9.2%
2018 CWE-400 1 PoC

A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

CVE-2024-7859
Visual Sound Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-1623
Custom Post Type UI Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.

CVE-2024-3963
Giveaways and Contests by RafflePress Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks