11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-11373
Connexion Logs Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-8398
Simple Nav Archives Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1204
Meta Box Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.

CVE-2024-4477
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting

CVE-2021-4396
Rucy Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Rucy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.4.4. This is due to missing or incorrect nonce validation on the save_rc_post_meta() function. This makes it possible for unauthenticated attackers to save post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-7820
ILC Thickbox Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2021-4423
RAYS Grid Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The RAYS Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the rsgd_insert_update() function. This makes it possible for unauthenticated attackers to update post fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-5772
Debug Log Manager – Conveniently Monitor and Inspect Errors Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-6857
WP MultiTasking Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2021-4390
Contact Form 7 Style Web Windows
4.3
MEDIUM
EPSS
0.1%
2021 CWE-352 7 PoCs

The Contact Form 7 Style plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2. This is due to missing or incorrect nonce validation on the manage_wp_posts_be_qe_save_post() function. This makes it possible for unauthenticated attackers to quick edit templates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-4400
Better Search – Relevant search results for WordPress Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on the bsearch_process_settings_import() and bsearch_process_settings_export() functions. This makes it possible for unauthenticated attackers to import and export settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-27594
SAP 3D Visual Enterprise Viewer Windows
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2021-4387
Opal Estate Web Windows
4.3
MEDIUM
EPSS
0.2%
2021 CWE-352 7 PoCs

The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to set and remove featured properties via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-1414
WP VR Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours

CVE-2024-3631
HL Twitter Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack

CVE-2023-0763
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack

CVE-2024-7892
adstxt Plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-13420
Benaa Framework Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-94 1 PoC

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.

CVE-2023-0495
HT Slider For Elementor Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6066
WP Custom Widget area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.