606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-8383
Depicter — Popup & Slider Builder Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-12494
Modula Image Gallery – Photo Grid & Video Gallery Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-285 1 PoC

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible for authenticated attackers, with author-level access and above, to move arbitrary image files on the server.

CVE-2025-15473
Timetics Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

CVE-2025-15520
RegistrationMagic Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.

CVE-2025-15527
WP Recipe Maker Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which posts can be retrieved. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from posts they may not be able to edit or read otherwise. This also affects password protected, private, or draft posts that they should not have access to.

CVE-2025-4580
File Provider Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-12189
Bread & Butter: AI-Powered Lead Intelligence Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 2 PoCs

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.11.1374. This is due to missing or incorrect nonce validation on the uploadImage() function. This makes it possible for unauthenticated attackers to upload arbitrary files that make remote code execution possible via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-13393
Featured Image from URL (FIFU) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.3.1. This is due to insufficient validation of user-supplied URLs before passing them to the getimagesize() function in the Elementor widget integration. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services via the fifu_input_url parameter in the FIFU Elementor widge

CVE-2025-10588
PixelYourSite – Your smart PIXEL (TAG) & API Manager Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 11.1.2. This is due to missing or incorrect nonce validation on the adminEnableGdprAjax() function. This makes it possible for unauthenticated attackers to modify GDPR settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-13794
Auto Featured Image (Auto Post Thumbnail) Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete or generate featured images on posts they do not own.

CVE-2025-1362
URL Shortener | Conversion Tracking | AB Testing | WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks

CVE-2025-9294
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-285 1 PoC

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete quiz results.

CVE-2025-5730
Contact Form Plugin Web Windows
4.3
MEDIUM
EPSS
0.2%
2025 1 PoC

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CVE-2025-11519
Optimole – Optimize Images in Real Time Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-639 1 PoC

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the /wp-json/optml/v1/move_image REST API endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to offload media that doesn't belong to them.

CVE-2025-2942
Order Delivery Date Web Windows
4.3
MEDIUM
EPSS
0.3%
2025 1 PoC

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

CVE-2025-1762
Event Tickets with Ticket Scanner Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 1 PoC

The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2025-8944
OceanWP Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 1 PoC

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

CVE-2025-14371
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.

CVE-2025-8595
Zakra Web Windows
4.3
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo settings.

CVE-2025-10700
Ally – Web Accessibility & Usability Web Windows
4.3
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on the enable_unfiltered_files_upload function. This makes it possible for unauthenticated attackers to enable unfiltered file upload and add svg files to the upload list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.