11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-8595
Zakra Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

CVE-2023-0497
HT Portfolio Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-3366
MultiParcels Shipping For WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

CVE-2023-4251
EventPrime Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.

CVE-2023-4023
All Users Messenger Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger.

CVE-2026-0929
RegistrationMagic Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

CVE-2023-0499
QuickSwish Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2026-1508
Court Reservation Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-9756
Order Attachments for WooCommerce Web Windows
4.3
MEDIUM
EPSS
4.1%
2024 CWE-862 1 PoC

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

CVE-2025-5730
Contact Form Plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2024-8082
Widgets Reset Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2026-1128
WP eCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could allow attackers to make a logged in admin remove them via a CSRF attack

CVE-2026-2687
Reading progressbar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-0554
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset analytics for any NotificationX campaign, regardless of ownership.

CVE-2024-11672
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

CVE-2025-1362
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

CVE-2026-1369
Conditional CAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2026-0658
Five Star Restaurant Reservations Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

CVE-2025-13794
Auto Featured Image (Auto Post Thumbnail) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete or generate featured images on posts they do not own.

CVE-2025-12189
Bread & Butter: AI-Powered Lead Intelligence Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 2 PoCs

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.