1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4485
Page-list Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4756
My YouTube Channel Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4676
OSM Web Windows
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4715
Structured Content (JSON-LD) #wpsc Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Structured Content WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3984
Flowplayer Video Player Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4480
Click to Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4655
Welcart e-Commerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack.

CVE-2022-4472
Simple Sitemap Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3739
WP Best Quiz Web Windows
5.4
MEDIUM
EPSS
1.8%
2022 1 PoC

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2022-4491
WP-Table Reloaded Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-4508
ConvertKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

CVE-2022-4749
Posts List Designer by Category Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4459
WP Show Posts Web Windows
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

The WP Show Posts WordPress plugin before 1.1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4716
WP Popups Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Popups WordPress plugin before 2.1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4005
Donation Button Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-4649
WP Extended Search Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4831
Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4787
Themify Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4763
Icon Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4670
PDF.js Viewer Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The PDF.js Viewer WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.