11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-8425
WooCommerce Ultimate Gift Card Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
42.7%
2024 CWE-434 2 PoCs

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added.

CVE-2025-2266
Checkout Mestres do WP for WooCommerce Web Windows
9.8
CRITICAL
EPSS
0.3%
2025 CWE-862 1 PoC

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2024-10470
WPLMS Learning Management System for WordPress, WordPress LMS Web Windows
9.8
CRITICAL
EPSS
48.5%
2024 CWE-22 2 PoCs

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.

CVE-2024-32459
FreeRDP Windows
9.8
CRITICAL
EPSS
6.4%
2024 CWE-125 1 PoC

FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.

CVE-2024-9047
Iptanus File Upload Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2024 CWE-22 5 PoCs

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.

CVE-2024-6028
Quiz Maker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2024 CWE-89 2 PoCs

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2015-10138
Work The Flow File Upload Web Windows
9.8
CRITICAL
EPSS
67.5%
2015 CWE-434 1 PoC

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2021-23274
TIBCO API Exchange Gateway Web Windows
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO API Exchange Gateway: versions 2.3.3 and below and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric: versions 2.3.3

CVE-2025-8047
disable-right-click-powered-by-pixterme Web Cloud Windows
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who control it, but it currently displays an alert marketing security services. Users that pay are added to allowedDomains to suppress the popup.

CVE-2025-6934
Opal Estate Pro – Property Management and Submission Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
28.0%
2025 CWE-269 9 PoCs

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user' function. This makes it possible for unauthenticated attackers to arbitrarily choose the role, including the Administrator role, assigned when registering.

CVE-2025-8570
BeyondCart Connector Web Windows
9.8
CRITICAL
EPSS
0.1%
2025 CWE-798 1 PoC

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within the determine_current_user filter in versions 1.4.2 through 3.0.1. This makes it possible for unauthenticated attackers to craft valid tokens and assume any user’s identity.

CVE-2024-6624
JSON API User Web Windows
9.8
CRITICAL
EPSS
43.5%
2024 CWE-269 2 PoCs

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

CVE-2023-6036
Web3 Web Windows
9.8
CRITICAL
EPSS
56.3%
2023 2 PoCs

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

CVE-2024-6265
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
32.9%
2024 CWE-89 0 PoCs

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-5084
Hash Form – Drag & Drop Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2024 CWE-434 7 PoCs

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-3136
MasterStudy LMS WordPress Plugin – for Online Courses and Education Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
54.2%
2024 CWE-98 1 PoC

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-11613
Iptanus File Upload Web Windows
9.8
CRITICAL
EPSS
75.1%
2024 CWE-94 2 PoCs

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.

CVE-2024-2667
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.7%
2024 CWE-434 2 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all versions up to, and including, 0.1.0.22. This makes it possible for unauthenticated attackers to upload arbitrary files.

CVE-2024-4434
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.1%
2024 CWE-89 1 PoC

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.