1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4358
WP RSS By Publishers Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3243
Import all XML, CSV & TXT into WordPress Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

CVE-2022-4351
Qe SEO Handyman Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-4370
multimedial images Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2022-3249
WP CSV Exporter Web Database Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks

CVE-2022-4352
Qe SEO Handyman Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3720
Event Monster Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

CVE-2022-1538
Theme Demo Import Web Windows
7.2
HIGH
EPSS
0.6%
2022 1 PoC

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.

CVE-2022-4356
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-4680
Revive Old Posts Web Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-2711
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-22 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

CVE-2022-3689
HTML Forms Web Database Windows
7.2
HIGH
EPSS
40.3%
2022 3 PoCs

The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-3425
Analyticator Web Windows
7.2
HIGH
EPSS
0.8%
2022 1 PoC

The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-4043
WP Custom Admin Interface Web Windows
7.2
HIGH
EPSS
1.2%
2022 1 PoC

The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-4268
Plugin Logic Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3380
Customizer Export/Import Web Windows
7.2
HIGH
EPSS
1.0%
2022 CWE-502 1 PoC

The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-3925
buddybadges Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-3858
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 1 PoC

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin.

CVE-2022-2352
Post SMTP Mailer/Email Log Web Windows
7.2
HIGH
EPSS
1.0%
2022 CWE-918 1 PoC

The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.

CVE-2022-3334
Easy WP SMTP Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.