606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-5815
Traffic Monitor Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.

CVE-2025-10638
NS Maintenance Mode for WP Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address

CVE-2025-11996
Find Unused Images Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the fui_delete_image() and fui_delete_all_images() functiosn in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to delete all of a site's attachments.

CVE-2025-9985
Featured Image from URL (FIFU) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
2.1%
2025 CWE-532 0 PoCs

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVE-2025-10645
WP Reset Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-532 1 PoC

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data.

CVE-2025-2568
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Web Windows
5.3
MEDIUM
EPSS
0.6%
2025 CWE-862 1 PoC

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the 'vayu_blocks_get_toggle_switch_values_callback' and 'vayu_blocks_save_toggle_switch_callback' function in versions 1.0.4 to 1.2.1. This makes it possible for unauthenticated attackers to read plugin options and update any option with a key name ending in '_value'.

CVE-2025-32098
Software Genérico Windows
5.3
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.

CVE-2025-12696
HelloLeads CRM Form Shortcode Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them

CVE-2025-4302
Stop User Enumeration Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.1%
2025 1 PoC

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

CVE-2025-14591
Delphix Continuous Compliance Windows
5.3
MEDIUM
EPSS
0.1%
2025 2 PoCs

In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.

CVE-2025-11237
Make Email Customizer for WooCommerce Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.

CVE-2025-14155
Premium Addons for Elementor – Powerful Elementor Templates & Widgets Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.7%
2025 CWE-862 1 PoC

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.

CVE-2025-9808
The Events Calendar Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.2%
2025 CWE-200 0 PoCs

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.

CVE-2025-14434
Ultimate Post Kit Addons for Elementor Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones.

CVE-2025-11703
WP Go Maps (formerly WP Google Maps) Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 CWE-349 1 PoC

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.

CVE-2025-13620
Wp Social Login and Register Social Counter Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 3.1.3. This is due to the REST routes wslu/v1/check_cache/{type}, wslu/v1/save_cache/{type}, and wslu/v1/settings/clear_counter_cache being registered with permission_callback set to __return_true and lacking capability or nonce validation in their handlers. This makes it possible for unauthenticated attackers to clear or overwrite the social counter cache via crafted REST requests.

CVE-2025-13471
User Activity Log Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)

CVE-2025-3939
Niagara Framework Windows
5.3
MEDIUM
EPSS
0.3%
2025 CWE-204 1 PoC

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11.Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-0466
Sensei LMS Web Windows
5.3
MEDIUM
EPSS
0.5%
2025 1 PoC

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

CVE-2025-4893
CoinExchange_CryptoExchange_Java Networking Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. This affects the function uploadLocalImage of the file /CoinExchange_CryptoExchange_Java-master/00_framework/core/src/main/java/com/bizzan/bitrade/util/UploadFileUtil.java of the component File Upload Endpoint. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information abo