1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6753
Social Auto Poster Web Windows ⚡ nuclei
7.2
HIGH
EPSS
5.0%
2024 CWE-79 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-8379
Cost Calculator Builder Web Database Windows
7.2
HIGH
EPSS
0.6%
2024 1 PoC

The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2024-5902
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Web Windows
7.2
HIGH
EPSS
3.5%
2024 CWE-79 1 PoC

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in feedback form responses that will execute whenever a high-privileged user tries to view them.

CVE-2024-5807
Business Card Web Windows
7.2
HIGH
EPSS
0.7%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.

CVE-2024-7129
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
7.2
HIGH
EPSS
12.7%
2024 1 PoC

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins

CVE-2024-10499
AI Engine Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-0566
Smart Manager Web Database Windows
7.2
HIGH
EPSS
2.5%
2024 2 PoCs

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2024-11269
AHAthat Plugin Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.

CVE-2024-6451
AI Engine Web Windows
7.2
HIGH
EPSS
0.7%
2024 1 PoC

AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.

CVE-2024-9022
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
7.2
HIGH
EPSS
1.6%
2024 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-13869
WPvivid — Backup, Migration & Staging Web Windows
7.2
HIGH
EPSS
21.9%
2024 CWE-434 2 PoCs

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload folder prevents

CVE-2024-9698
Crafthemes Demo Import Web Windows
7.2
HIGH
EPSS
46.9%
2024 CWE-434 1 PoC

The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-13888
WPMobile.App Web Windows ⚡ nuclei
7.2
HIGH
EPSS
1.9%
2024 CWE-601 0 PoCs

The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

CVE-2024-6354
Remote Desktop Manager Windows
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

CVE-2024-9831
Taskbuilder Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-27775
SysAid Windows
7.2
HIGH
EPSS
0.1%
2024 CWE-918 1 PoC

SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash

CVE-2024-8349
Uncanny Groups for LearnDash Web Windows
7.2
HIGH
EPSS
4.0%
2024 CWE-862 1 PoC

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

CVE-2024-8699
Z-Downloads Web Windows
7.2
HIGH
EPSS
0.9%
2024 1 PoC

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2024-4439
WordPress Web Windows ⚡ nuclei
7.2
HIGH
EPSS
90.8%
2024 5 PoCs

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. In addition, it also makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that have the comment block present and display the comment author's avatar.

CVE-2024-11372
Connexion Logs Web Database Windows
7.2
HIGH
EPSS
1.3%
2024 1 PoC

The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks