606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-10684
Construction Light Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

CVE-2025-10476
WP Fastest Cache – WordPress Cache Plugin Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpfc_db_fix_callback() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to initiate several database fix actions. This only affects sites with premium activated.

CVE-2025-11587
Call Now Button – The #1 Click to Call Button for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to link the plugin to their nowbuttons.com account and add malicious buttons to the site. The vulnerability is only exploitable on fresh installs where the plugin has not been previously configured with an API key.

CVE-2025-3942
Niagara Framework Windows
4.3
MEDIUM
EPSS
0.2%
2025 CWE-117 2 PoCs

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-9703
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.

CVE-2025-9979
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

CVE-2025-5526
BuddyPress Docs Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user

CVE-2025-9331
Spacious Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

CVE-2025-12971
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to move arbitrary folder contents to arbitrary folders.

CVE-2025-14163
Premium Addons for Elementor – Powerful Elementor Templates & Widgets Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible for unauthenticated attackers to create arbitrary Elementor templates via a forged request granted they can trick a site administrator or other user with the edit_posts capability into performing an action such as clicking on a link.

CVE-2025-13749
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for unauthenticated attackers to disable plugin/theme update notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-8669
Customify Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing or incorrect nonce validation on the reset_customize_section function. This makes it possible for unauthenticated attackers to reset theme customization settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-13753
WP Table Builder – Drag & Drop Table Builder Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-863 1 PoC

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect authorization check on the save_table() function in all versions up to, and including, 2.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new wptb-table posts.

CVE-2025-9888
Maspik – Ultimate Spam Protection Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-8891
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-0748
Homey Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the 'homey_verify_user_manually' function. This makes it possible for unauthenticated attackers to update verify an user via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-6790
Quiz and Survey Master (QSM) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2025-12377
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Author-level access and above, to perform multiple actions, such as removing images from arbitrary galleries. The vulnerability was partially patched in version 1.12.0.

CVE-2025-8383
Depicter — Popup & Slider Builder Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-12494
Modula Image Gallery – Photo Grid & Video Gallery Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above, to move arbitrary image files on the server.