11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-3178
POST SMTP Mailer Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.

CVE-2022-3923
ActiveCampaign for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

CVE-2022-23180
Contact Form & Lead Form Elementor Builder Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings

CVE-2022-4004
Donation Button Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donation_button_twilio_send_test_sms" AJAX action, which may allow any users with an account on the affected site, like subscribers, to use the plugin's Twilio integration to send SMSes to arbitrary phone numbers.

CVE-2022-4872
Chained Products Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ensure that the option to be updated belong to the plugin, allowing unauthenticated attackers to set arbitrary options to 'no'

CVE-2022-2460
WPDating Web Database Windows
4.3
MEDIUM
EPSS
4.4%
2022 1 PoC

The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL queries, leading to multiple SQL injection vulnerabilities exploitable by unauthenticated users

CVE-2023-0496
HT Event Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2018-13374
🔥 KEV Fortinet FortiOS, fortiADC Networking Windows
4.3
MEDIUM
EPSS
3.8%
2018 1 PoC

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVE-2023-0503
Free WooCommerce Theme 99fy Extension Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2018-10919
samba Windows
4.3
MEDIUM
EPSS
1.4%
2018 CWE-203 1 PoC

The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

CVE-2020-36746
Menu Swapper Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0.2. This is due to missing or incorrect nonce validation on the mswp_save_meta() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36735
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.3. This is due to missing or incorrect nonce validation on the handle_leave_calendar_filter, add_enable_disable_option_save, leave_policies, process_bulk_action, and process_crm_contact functions. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36750
EWWW Image Optimizer Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The EWWW Image Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.1. This is due to missing or incorrect nonce validation on the ewww_ngg_bulk_init() function. This makes it possible for unauthenticated attackers to perform bulk image optimization via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36737
Import / Export Customizer Settings Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Import / Export Customizer Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the astra_admin_errors() function. This makes it possible for unauthenticated attackers to display an import status via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0453
WP Private Message Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVE-2020-36757
WP Hotel Booking Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-5531
Thumbnail Slider With Lightbox Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36749
Easy Testimonials Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Easy Testimonials plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36751
Coupon Creator Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Coupon Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_meta() function. This makes it possible for unauthenticated attackers to save meta fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36742
Custom Field Template Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the edit_meta_value() function. This makes it possible for unauthenticated attackers to edit meta field values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.