11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-10510
adBuddy+ (AdBlocker Detection) by NetfunkDesign Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10518
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Web Windows
4.8
MEDIUM
EPSS
0.6%
2024 1 PoC

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.15 does not sanitise and escape some of its Membership Plan settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11183
Simple Side Tab Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-1614
WP Custom Author URL Web Windows
4.8
MEDIUM
EPSS
0.4%
2023 1 PoC

The WP Custom Author URL WordPress plugin before 1.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8426
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-8378
Safe SVG Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.

CVE-2024-7716
Logo Slider Web Windows
4.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11645
float block Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10143
MB Custom Post Types & Custom Taxonomies Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-0974
Social Media Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2263
Themify Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-13602
Poll Maker Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8617
Quiz Maker Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Quiz Maker WordPress plugin before 6.5.9.9 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-7115
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8284
Download Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-13313
AWeber Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-2658
WP Spell Check Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-3499
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4196
Multi Step Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-25117
WP-PostRatings Web Windows
4.8
MEDIUM
EPSS
0.2%
2021 1 PoC

The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF attacks, the issue is still exploitable when the unfiltered_html capability is disabled.