11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-4382
CB (legacy) Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

CVE-2025-13794
Auto Featured Image (Auto Post Thumbnail) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete or generate featured images on posts they do not own.

CVE-2025-12189
Bread & Butter: AI-Powered Lead Intelligence Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 2 PoCs

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-1330
kadence-blocks-pro Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

CVE-2024-7862
blogintroduction-wordpress-plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-4580
File Provider Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-3163
Easy Property Listings Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2023-3707
ActivityPub Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.

CVE-2024-9583
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-862 1 PoC

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.

CVE-2024-8157
Alphabetical List Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-3601
Simple Author Box Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.

CVE-2023-4836
WordPress File Sharing Plugin Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 2 PoCs

The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

CVE-2025-15473
Timetics Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

CVE-2024-11842
DN Shipping by Weight for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-6741
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.

CVE-2024-12709
Bulk Me Now! Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2025-0748
Homey Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the 'homey_verify_user_manually' function. This makes it possible for unauthenticated attackers to update verify an user via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-8891
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-12750
Competition Form Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-2287
Orbit Fox by ThemeIsle Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.