11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-0097
Post Grid, Post Carousel, & List Category Posts Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6141
Essential Real Estate Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.

CVE-2023-0230
VK All in One Expansion Unit Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0363
Scheduled Announcements Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Scheduled Announcements Widget WordPress plugin before 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0368
Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0418
Video Central for WordPress Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0891
StagTools Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6499
lasTunes Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-6081
chartjs Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-11378
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF Web Windows
5.4
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to export and import site options.

CVE-2023-0079
Customer Reviews for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0380
Easy Digital Downloads Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4829
Show-Hide / Collapse-Expand Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Show-Hide / Collapse-Expand WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4476
Download Manager Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

CVE-2022-4481
Mesmerize Companion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2019-19981
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.1%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

CVE-2023-7085
Scalable Vector Graphics (SVG) Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-0405
GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.

CVE-2023-0823
Cookie Notice & Compliance for GDPR / CCPA Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.4.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2025-1454
Ninja Pages Web Windows
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).