1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4677
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4464
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privileged users such as admin.

CVE-2022-4629
Product Slider for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Product Slider for WooCommerce WordPress plugin before 2.6.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4394
iPages Flipbook For WordPress Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-4824
WP Blog and Widgets Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3987
Responsive Lightbox2 Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4756
My YouTube Channel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4717
Strong Testimonials Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4676
OSM Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-3984
Flowplayer Video Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4475
Collapse-O-Matic Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

CVE-2022-4825
WP-ShowHide Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-ShowHide WordPress plugin before 1.05 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4655
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.

CVE-2022-3933
Essential Real Estate Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
5.5%
2022 1 PoC

The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks.

CVE-2022-4675
Mongoose Page Plugin Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4472
Simple Sitemap Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-2413
Slide Anything Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting it in the admin pages, allowing a logged in user with roles as low as Author to inject a javascript payload into the slide title even when the unfiltered_html capability is disabled.

CVE-2022-4749
Posts List Designer by Category Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3739
WP Best Quiz Web Windows
5.4
MEDIUM
EPSS
1.8%
2022 1 PoC

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2022-4657
Restaurant Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks