11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4678
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2025-1454
Ninja Pages Web Windows
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0292
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Web Windows
5.4
MEDIUM
EPSS
0.5%
2023 CWE-352 1 PoC

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to missing nonce validation on the function associated with the qsm_remove_file_fd_question AJAX action. This makes it possible for unauthenticated attackers to delete arbitrary media files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0175
Responsive Clients Logo Gallery Plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0146
Naver Map Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0490
f(x) TOC Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The f(x) TOC WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0559
GS Portfolio for Envato Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2017-3907
Threat Intelligence Exchange (TIE) Server Windows
5.4
MEDIUM
EPSS
0.5%
2017 1 PoC

Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.

CVE-2023-6485
Html5 Video Player Web Windows
5.4
MEDIUM
EPSS
1.9%
2023 1 PoC

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins

CVE-2023-0074
WP Social Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0271
WP Font Awesome Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Font Awesome WordPress plugin before 1.7.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1905
WP Popups Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003

CVE-2023-0252
Contextual Related Posts Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0282
YourChannel: Everything you want in a YouTube plugin. Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

CVE-2023-0150
Cloak Front End Email Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4757
Staff / Employee Business Directory for Active Directory Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.

CVE-2023-4035
Simple Blog Card Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-6530
TJ Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-7246
System Dashboard Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
1.5%
2023 1 PoC

The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks

CVE-2025-4133
Blog2Social: Social Media Auto Post & Scheduler Web Windows
5.4
MEDIUM
EPSS
0.1%
2025 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.