11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-3752
Crelly Slider Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-12722
Twitter Bootstrap Collapse aka Accordian Shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-4094
Simple Share Buttons Adder Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-0096
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3026
WordPress Button Plugin MaxButtons Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-3965
Pray For Me Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-0374
W4 Post List Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5942
Medialist Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-6754
Social Auto Poster Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary post metadata.

CVE-2022-4629
Product Slider for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Product Slider for WooCommerce WordPress plugin before 2.6.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4765
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-1755
SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

CVE-2024-10482
Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2024-11502
Planning Center Online Giving Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6074
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0367
Pricing Tables For WPBakery Page Builder (formerly Visual Composer) Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4551
Rich Table of Contents Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5074
wp-eMember Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-6710
Ditty Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2023-4035
Simple Blog Card Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks