11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-4057
Gutenberg Blocks with AI by Kadence WP Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-6720
Light Poll Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-11849
Pods Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-12682
Smart Maintenance Mode Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2023
Custom 404 Pro Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
80.9%
2023 2 PoCs

The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2023-6000
Popup Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
69.1%
2023 4 PoCs

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CVE-2025-13153
Logo Slider Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1660
AI ChatBot Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard

CVE-2024-7822
Quick Code Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-13331
WP Dream Carousel Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.1%
2024 1 PoC

The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5811
Simple Video Directory Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2025-1798
design-comuni-wordpress-theme Web Windows
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.

CVE-2024-4924
Social Sharing Plugin Web Windows
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6272
SpiderContacts Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-7194
Meris Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-3580
Popup4Phone Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4151
Store Locator WordPress Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
13.9%
2023 1 PoC

The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-11503
WP Tabs Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-2203
FunnelKit Web Database Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-12734
Advance Post Prefix Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.