11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-36756
10WebAnalytics Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The 10WebAnalytics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. This is due to missing or incorrect nonce validation on the create_csv_file() function. This makes it possible for unauthenticated attackers to create a CSV file via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36742
Custom Field Template Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Custom Field Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on the edit_meta_value() function. This makes it possible for unauthenticated attackers to edit meta field values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36755
Customizr Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Customizr theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.0. This is due to missing or incorrect nonce validation on the czr_fn_post_fields_save() function. This makes it possible for unauthenticated attackers to post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36743
Product Catalog Simple Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Product Catalog Simple plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.13. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to update product meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36760
Ocean Extra Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36752
Coming Soon & Maintenance Mode Page & Under Construction Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save meta boxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36740
Radio Buttons for Taxonomies Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 8 PoCs

The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the save_single_term() function. This makes it possible for unauthenticated attackers to save terms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-6289
Swift Performance Lite Web Cloud Windows
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

CVE-2020-36747
Lightweight Sidebar Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Lightweight Sidebar Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the metabox_save() function. This makes it possible for unauthenticated attackers to save metbox data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36741
MultiVendorX – WooCommerce Multivendor Marketplace Solutions Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The MultiVendorX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.7. This is due to missing or incorrect nonce validation on the submit_comment() function. This makes it possible for unauthenticated attackers to submit comments via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0498
WP Education Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2020-36759
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-11019
FreeRDP Windows
4.3
MEDIUM
EPSS
0.4%
2020 CWE-125 2 PoCs

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index. Data could be printed as string to local terminal. This has been fixed in 2.1.0.

CVE-2022-4553
FL3R FeelBox Web Windows
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables

CVE-2020-36738
Cool Timeline (Horizontal & Vertical Timeline) Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Cool Timeline (Horizontal & Vertical Timeline) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the ctl_save() function. This makes it possible for unauthenticated attackers to save field icons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-3923
ActiveCampaign for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs.

CVE-2020-36736
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The WooCommerce Checkout & Funnel Builder by CartFlows plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.15. This is due to missing or incorrect nonce validation on the export_json, import_json, and status_logs_file functions. This makes it possible for unauthenticated attackers to import/export settings and trigger logs showing via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36739
Feed Them Social – Social Media Feeds, Video, and Photo Galleries Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Feed Them Social – Page, Post, Video, and Photo Galleries plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the my_fts_fb_load_more() function. This makes it possible for unauthenticated attackers to load feeds via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-0505
Ever Compare Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2020-36754
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.