11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-10634
Nokaut Offers Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack

CVE-2025-9888
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1088
WP Plugin Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2025-8891
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-6501
Splashscreen Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-5169
Video Widget Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2025-12971
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

CVE-2023-0762
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack

CVE-2025-5526
BuddyPress Docs Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user

CVE-2024-10677
BTEV Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-10684
Construction Light Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVE-2023-1911
Blocksy Companion Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example

CVE-2024-1319
Events Tickets Plus Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).

CVE-2023-6633
Site Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks

CVE-2023-6292
Ecwid Ecommerce Shopping Cart Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2025-14371
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.

CVE-2025-8944
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

CVE-2024-12280
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack

CVE-2025-1762
Event Tickets with Ticket Scanner Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-2942
Order Delivery Date Web Windows
4.3
MEDIUM
EPSS
0.3%
2025 1 PoC

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information