11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-13031
WPeMatico RSS Feed Fetcher Web Windows
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-11357
goodlayers-core Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2026-40355
Kerberos 5 Windows
5.9
MEDIUM
EPSS
0.1%
2026 CWE-476 1 PoC

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

CVE-2026-40356
Kerberos 5 Windows
5.9
MEDIUM
EPSS
0.1%
2026 CWE-191 1 PoC

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

CVE-2025-3516
Simple Lightbox Web Windows
5.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6390
Quiz and Survey Master (QSM) Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2026-1867
Guest posting / Frontend Posting / Front Editor Web Windows
5.9
MEDIUM
EPSS
0.1%
2026 1 PoC

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to regenerate a .json file based on demo data that it initially creates. If an administrator modifies the demo form and enables admin notifications in the Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6's settings, it is possible for an unauthenticated attacker to export and download all of the form data/settings, including the administrator's email address.

CVE-2024-13609
1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
17.7%
2024 CWE-200 0 PoCs

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.

CVE-2024-5075
wp-eMember Web Windows
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-2279
Maps Web Windows
5.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-2310
WP Google Review Slider Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4096
Responsive Tabs Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

CVE-2025-6572
OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Web Windows
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-5573
Easy Table of Contents Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-9230
PowerPress Podcasting plugin by Blubrry Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks

CVE-2024-10472
Stylish Price List Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-0904
Fancy Product Designer Web Windows
5.9
MEDIUM
EPSS
0.4%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4753
WP Secure Maintenance Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2025-15363
Get Use APIs Web Windows
5.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations.

CVE-2024-5442
Photo Gallery, Sliders, Proofing and Themes Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).