11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-5286
wp-affiliate-platform Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2022-1094
amr users Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2024-1663
Ultimate Noindex Nofollow Tool II Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3922
Broken Link Checker Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6797
DL Robots.txt Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3832
External Media Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6722
Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13053
Form Maker by 10Web Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2489
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3631
OAuth Client by DigitialPixies Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2024-9641
LuckyWP Table of Contents Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8618
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4664
WP Chat App Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-7769
ClickSold IDX Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-1554
Quick Paypal Payments Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-13128
LearnPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5229
E2Pdf Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2024-10475
Responsive Contact Form Builder & Lead Generation Plugin Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3918
Pet Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.

CVE-2024-5561
Popup Maker Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)