11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-36753
Hueman Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save metabox data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36748
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Web Windows
4.3
MEDIUM
EPSS
0.1%
2020 CWE-352 7 PoCs

The Dokan plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.8. This is due to missing or incorrect nonce validation on the handle_order_export() function. This makes it possible for unauthenticated attackers to trigger an order export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1939
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.

CVE-2020-36744
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the generate_conversions() function. This makes it possible for unauthenticated attackers to generate conversions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36639
AMX Mod X Windows
4.3
MEDIUM
EPSS
0.7%
2020 CWE-22 1 PoC

A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affects the function cmdVoteMap of the file plugins/adminvote.sma of the component Console Command Handler. The manipulation of the argument amx_votemap leads to path traversal. The patch is identified as a5f2b5539f6d61050b68df8b22ebb343a2862681. It is recommended to apply a patch to fix this issue. VDB-217354 is the identifier assigned to this vulnerability.

CVE-2020-36761
WebberZone Top 10 — Popular Posts Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The Top 10 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.4. This is due to missing or incorrect nonce validation on the tptn_export_tables() function. This makes it possible for unauthenticated attackers to generate an export of the top 10 table via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2020-36745
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Web Windows
4.3
MEDIUM
EPSS
0.2%
2020 CWE-352 7 PoCs

The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-11762
HubSpot All-In-One Marketing – Forms, Popups, Live Chat Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.32 via the leadin/public/admin/class-adminconstants.php file. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract a list of all installed plugins and their versions which can be leveraged for reconnaissance and further attacks.

CVE-2025-11369
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with Author-level access and above, to view API keys configured for the external services.

CVE-2025-9703
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

CVE-2023-0761
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack

CVE-2025-11587
Call Now Button – The #1 Click to Call Button for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to link the plugin to their nowbuttons.com account and add malicious buttons to the site. The vulnerability is only exploitable on fresh installs where the plugin has not been previously configured with an API key.

CVE-2023-6625
Product Enquiry for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2023-1089
Coupon Zen Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2025-9979
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

CVE-2025-7965
CBX Restaurant Booking Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-9202
ColorMag Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.

CVE-2025-8682
Newsup Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin.

CVE-2025-10700
Ally – Web Accessibility & Usability Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-4150
User Activity Tracking and Log Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks