11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-38467
CRM Perks Forms – WordPress Form Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
17.7%
2022 CWE-79 0 PoCs

Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

CVE-2022-4971
Social Sharing Plugin – Sassy Social Share Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
10.1%
2022 CWE-79 1 PoC

The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter called via the 'heateor_sss_sharing_count' AJAX action in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-3032
Themify Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.5%
2024 1 PoC

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2024-5729
Simple AL Slider Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-10103
MailPoet Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

CVE-2022-4368
WP CSV Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP CSV WordPress plugin through 1.8.0.0 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, and doe snot have CSRF checks in place as well, leading to a Reflected Cross-Site Scripting.

CVE-2024-0250
Analytics Insights for Google Analytics 4 (AIWP) Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
21.2%
2024 1 PoC

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-5282
wp-affiliate-platform Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2654
Conditional Menus Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0948
Japanized For WooCommerce Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
22.9%
2023 1 PoC

The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2024-12772
Ninja Tables Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability.

CVE-2023-7200
EventON Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-1473
Slider, Gallery, and Carousel by MetaSlider Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-7860
Simple Headline Rotator Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-2203
FunnelKit Web Database Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-12585
Property Hive Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 1 PoC

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-12873
Custom Field Manager Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-4826
socialdriver Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.

CVE-2024-11107
System Dashboard Web Windows
6.1
MEDIUM
EPSS
1.7%
2024 1 PoC

The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2023-2571
Quiz Maker Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.2.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin