606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-0466
Sensei LMS Web Windows
5.3
MEDIUM
EPSS
0.5%
2025 1 PoC

The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_email and sensei_message Information.

CVE-2025-4893
CoinExchange_CryptoExchange_Java Networking Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d3efbeeb2473d7235bd01436fa. This affects the function uploadLocalImage of the file /CoinExchange_CryptoExchange_Java-master/00_framework/core/src/main/java/com/bizzan/bitrade/util/UploadFileUtil.java of the component File Upload Endpoint. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information abo

CVE-2025-6082
Birth Chart Compatibility Web Windows
5.3
MEDIUM
EPSS
3.6%
2025 CWE-200 1 PoC

The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to insufficient protection against directly accessing the plugin's index.php file, which causes an error exposing the full path. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

CVE-2025-9196
Trinity Audio – Text to Speech AI audio player to convert content into audio Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.5%
2025 CWE-200 1 PoC

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

CVE-2025-8999
Sydney Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions up to, and including, 2.56. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate various theme modules.

CVE-2025-10873
ElementInvader Addons for Elementor Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the elementinvader_addons_for_elementor_forms_send_form action.

CVE-2025-10579
BackWPup – WordPress Backup & Restore Plugin Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'backwpup_working' AJAX action in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve access to a back-up's filename while a backup is running. This information has little value on it's own, but could be used to aid in a brute force attack to retrieve back-up contents in limited environments (i.e. NGINX).

CVE-2025-12696
HelloLeads CRM Form Shortcode Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them

CVE-2025-11171
Chartify – WordPress Chart Plugin Web Windows
5.3
MEDIUM
EPSS
0.5%
2025 CWE-306 1 PoC

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, without any nonce or capability checks. This makes it possible for unauthenticated attackers to execute administrative functions via the wp-admin/admin-ajax.php endpoint granted they can identify callable method names.

CVE-2025-11191
RealPress Web Windows
5.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

CVE-2025-11072
MelAbu WP Download Counter Button Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files.

CVE-2025-13820
Comments Web Windows
5.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

CVE-2025-26263
Software Genérico Windows
5.1
MEDIUM
EPSS
0.3%
2025 1 PoC

GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.

CVE-2025-32103
CrushFTP Windows
5.0
MEDIUM
EPSS
1.6%
2025 CWE-40 2 PoCs

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames, bypassing SecurityManager restrictions.

CVE-2025-3471
SureForms Web Windows
4.9
MEDIUM
EPSS
0.2%
2025 1 PoC

The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action

CVE-2025-10046
ELEX WooCommerce Google Shopping (Google Product Feed) Web Database Windows
4.9
MEDIUM
EPSS
0.1%
2025 CWE-89 1 PoC

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-12630
Upload.am Web Windows
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users such as contributor to view site options.

CVE-2025-3470
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
4.9
MEDIUM
EPSS
0.2%
2025 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2025-14719
Relevanssi Web Database Windows
4.9
MEDIUM
EPSS
0.0%
2025 1 PoC

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVE-2025-9345
File Manager, Code Editor, and Backup by Managefy Web Windows
4.9
MEDIUM
EPSS
0.1%
2025 CWE-22 1 PoC

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.