11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-0060
Responsive Gallery Grid Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6134
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-3630
HL Twitter Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12768
Responsive iframe Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Responsive iframe WordPress plugin through 1.2.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4451
Social Sharing Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-0399
Image Over Image For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0542
Custom Post Type List Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4625
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-0072
WC Vendors Marketplace Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4381
Popup Maker Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2023-0033
PDF Viewer Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The PDF Viewer WordPress plugin before 1.0.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2024-29865
Software Genérico Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

CVE-2022-4826
Simple Tooltips Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-6884
Gutenberg Blocks with AI by Kadence WP Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-6710
Ditty Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2023-0537
Product Slider For WooCommerce Lite Web Windows
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

The Product Slider For WooCommerce Lite WordPress plugin through 1.1.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-9238
AVIF Uploader Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-1746
Testimonial Slider Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0360
Location Weather Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4475
Collapse-O-Matic Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.