11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-11519
Optimole – Optimize Images in Real Time Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-639 1 PoC

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to offload media that doesn't belong to them.

CVE-2024-1279
Paid Memberships Pro Web Windows
4.3
MEDIUM
EPSS
0.5%
2024 1 PoC

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

CVE-2023-3126
B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to retrieve the full pricing list of all products on the site.

CVE-2024-2429
Salon booking system Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-4297
Mmm Simple File List Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.

CVE-2023-4307
Lock User Account Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack

CVE-2023-7125
Community by PeepSo Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

CVE-2024-9926
Jetpack Web Windows
4.3
MEDIUM
EPSS
22.8%
2024 1 PoC

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

CVE-2024-34029
Mattermost Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.

CVE-2025-6790
Quiz and Survey Master (QSM) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2025-13753
WP Table Builder – Drag & Drop Table Builder Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

CVE-2025-8669
Customify Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing or incorrect nonce validation on the reset_customize_section function. This makes it possible for unauthenticated attackers to reset theme customization settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-8009
Sensei LMS Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

CVE-2023-39203
Zoom Rooms Client for Windows and Zoom VDI Client Windows
4.3
MEDIUM
EPSS
0.2%
2023 CWE-789 1 PoC

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2025-13749
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attackers to disable plugin/theme update notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-9331
Spacious Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

CVE-2025-3942
Niagara Framework Windows
4.3
MEDIUM
EPSS
0.2%
2025 CWE-117 2 PoCs

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-10476
WP Fastest Cache – WordPress Cache Plugin Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.

CVE-2024-3477
Popup Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks

CVE-2023-3244
Comments Like Dislike Web Windows
4.3
MEDIUM
EPSS
3.3%
2023 CWE-862 1 PoC

The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: this issue is was only partially patched in version 1.2.0, as the nonce is still present to subscriber-level users.