11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4786
Video.js Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0272
NEX-Forms Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0070
ResponsiveVoice Text To Speech Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0540
GS Filterable Portfolio Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4625
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-0546
Contact Form Plugin Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins previewing or editing the form.

CVE-2025-1454
Ninja Pages Web Windows
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0370
WPB Advanced FAQ Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-28665
Woo Bulk Price Update WordPress Plugin Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
21.8%
2023 1 PoC

The Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'page' parameter to the techno_get_products action, which can only be triggered by an authenticated user.

CVE-2023-0069
WPaudio MP3 Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0151
uTubeVideo Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4289
WP Matterport Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Matterport Shortcode WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-3194
Dokan Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

CVE-2021-24366
Admin Columns Web Windows
5.4
MEDIUM
EPSS
0.4%
2021 1 PoC

The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0153
Vimeo Video Autoplay Automute Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Vimeo Video Autoplay Automute WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4448
GiveWP Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4795
Testimonial Slider Shortcode Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

CVE-2023-0376
Qubely Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-7084
Voting Record Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks

CVE-2021-4417
Forminator Forms – Contact Form, Payment Form & Custom Form Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4. This is due to missing or incorrect nonce validation on the listen_for_saving_export_schedule() function. This makes it possible for unauthenticated attackers to export form submissions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.