606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-1286
Download HTML TinyMCE Button Web Windows
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-6174
Qwizcards | online quizzes and flashcards Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2025 1 PoC

The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or any other user.

CVE-2025-7022
My Reservation System Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-9034
Wp Edit Password Protected Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2025-3662
FancyBox for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS

CVE-2025-0368
Banner Garden Plugin for WordPress Web Windows
6.1
MEDIUM
EPSS
0.5%
2025 1 PoC

The Banner Garden Plugin for WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users.

CVE-2025-9163
Houzez Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 CWE-79 1 PoC

The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping in the houzez_property_img_upload() and houzez_property_attachment_upload() functions. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2025-13456
ShopBuilder Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-4429
Gearside Developer Dashboard Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-1798
design-comuni-wordpress-theme Web Windows
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.

CVE-2025-14313
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-14312
Advance WP Query Search Filter Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-1288
WOOEXIM Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.

CVE-2025-7808
WP Shopify Web Windows
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2025-1303
Plugin Oficial Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

CVE-2025-2203
FunnelKit Web Database Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2025-1382
Contact Us By Lord Linus Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-0671
Icegram Express Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2025-4652
Broadstreet Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-13153
Logo Slider Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting them back in the dashboard, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.