1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4657
Restaurant Menu Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4005
Donation Button Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2022-4749
Posts List Designer by Category Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-3739
WP Best Quiz Web Windows
5.4
MEDIUM
EPSS
1.8%
2022 1 PoC

The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

CVE-2022-4509
Content Control Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.

CVE-2022-4679
Wufoo Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Wufoo Shortcode WordPress plugin before 1.52 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4831
Custom User Profile Fields for User Registration & Member Frontend Profiles with Paid Memberships Pro Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4649
WP Extended Search Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4763
Icon Widget Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4670
PDF.js Viewer Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The PDF.js Viewer WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-4787
Themify Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2022-4381
Popup Maker Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4678
TemplatesNext ToolKit Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2022-3986
WP Stripe Checkout Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2022-4718
Landing Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4114
Superio Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.

CVE-2022-4480
Click to Chat Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4783
Youtube Channel Gallery Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2022-4667
RSS Aggregator by Feedzy Web Windows
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2022-4487
Easy Accordion Web Windows
5.4
MEDIUM
EPSS
0.3%
2022 1 PoC

The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.