11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1651
AI ChatBot Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allowing any authenticated users, such as subscriber to update them. Furthermore, due to the lack of escaping of the settings, this could also lead to Stored XSS

CVE-2024-2837
WP Chat App Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-4571
Seriously Simple Podcasting Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3024
Bitcoin Satoshi Tools : Faucets, Visitor Rewarder, Satoshi Games, Referral Program Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 CWE-863 1 PoC

The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues

CVE-2024-9020
List category posts Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0371
EmbedSocial Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4675
Mongoose Page Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2024-3058
ENL Newsletter Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-0333
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-6536
Zephyr Project Manager Web Windows
5.4
MEDIUM
EPSS
52.0%
2024 2 PoCs

The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4825
WP-ShowHide Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-ShowHide WordPress plugin before 1.05 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2024-1846
Responsive Tabs Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4765
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2024-4483
Email Encoder Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

CVE-2022-1755
SVG Support Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with a role as low as author to perform Cross-Site Scripting attacks

CVE-2024-13826
Email Keep Web Windows
5.4
MEDIUM
EPSS
0.0%
2024 1 PoC

The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2023-0373
Lightweight Accordion Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4787
Themify Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2024-6668
ProfilePro Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks