11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6668
ProfilePro Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks

CVE-2024-4270
SVGMagic Web Windows
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-13097
WP Finance Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
3.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-1454
Ninja Pages Web Windows
5.4
MEDIUM
EPSS
0.2%
2025 1 PoC

The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10896
Logo Slider Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting

CVE-2022-4673
Rate my Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Rate my Post WordPress plugin before 3.3.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4449
Page scroll to id Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4716
WP Popups Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Popups WordPress plugin before 2.1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4836
Breadcrumb Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2024-5440
If-So Dynamic Content Personalization Web Windows
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4625
Login Logout Menu Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-0094
UpQode Google Maps Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3978
WordPress Jitsi Shortcode Web Windows
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4833
YourChannel: Everything you want in a YouTube plugin. Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2023-28664
Meta Data and Taxonomies Filter WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user.

CVE-2023-0362
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-6136
wp-cart-for-digital-products Web Windows
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2023-0379
Spotlight Social Feeds [Block, Shortcode, and Widget] Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0372
EmbedStories Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-8092
Accordion Image Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.