11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-4036
Simple Blog Card Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

CVE-2021-4410
Qtranslate Slug Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.18. This is due to missing or incorrect nonce validation on the save_postdata() function. This makes it possible for unauthenticated attackers to save post data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-5352
Awesome Support Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

CVE-2021-4420
Sell Media Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the sell_media_process() function. This makes it possible for unauthenticated attackers to sell media paypal orders via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4402
Multiple Roles Web Windows
4.3
MEDIUM
EPSS
0.3%
2021 CWE-352 7 PoCs

The Multiple Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the mu_add_roles_in_signup_meta() and mu_add_roles_in_signup_meta_recently() functions. This makes it possible for unauthenticated attackers to add additional roles to users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4389
WP Travel – Ultimate Travel Booking System, Tour Management Engine Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The WP Travel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.6. This is due to missing or incorrect nonce validation on the save_meta_data() function. This makes it possible for unauthenticated attackers to save metadata for travel posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-3545
Server Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.

CVE-2021-4407
Custom Banners Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4391
Ultimate Gift Cards for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the mwb_wgm_save_post() function. This makes it possible for unauthenticated attackers to modify product gift card details via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4395
Abandoned Cart Recovery for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on the get_items() and extra_tablenav() functions. This makes it possible for unauthenticated attackers to perform read-only actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4394
Locations Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Locations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to update custom field meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-4474
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
2.8%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2021-4425
Defender Security – Malware Scanner, Login Security & Firewall Web Networking Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Defender Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the verify_otp_login_time() function. This makes it possible for unauthenticated attackers to verify a one time login via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4414
Abandoned Cart Lite for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it possible for unauthenticated attackers to generate email preview templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4422
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Web Windows
4.3
MEDIUM
EPSS
0.3%
2021 CWE-352 7 PoCs

The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4403
Remove Schema Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-4969
Widget Bundle Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

CVE-2023-7198
WP Dashboard Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.

CVE-2024-13306
Maps Plugin using Google Maps for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2021-4419
WP-Backgrounds Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the ino_save_data() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.