1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3982
Booking calendar, Appointment Booking System Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.2%
2022 1 PoC

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

CVE-2022-33198
Accordions (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
31.2%
2022 CWE-264 0 PoCs

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

CVE-2022-4681
Hide My WP Web Database Windows
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-4063
InPost Gallery Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.0%
2022 1 PoC

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

CVE-2022-3921
Listingo Web Windows
9.8
CRITICAL
EPSS
7.8%
2022 1 PoC

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE

CVE-2022-4395
Membership For WooCommerce Web Windows
9.8
CRITICAL
EPSS
76.3%
2022 3 PoCs

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

CVE-2022-3477
tagDiv Composer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.5%
2022 CWE-287 1 PoC

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

CVE-2022-3254
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.6%
2022 CWE-89 1 PoC

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

CVE-2022-0651
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
69.4%
2022 CWE-89 0 PoCs

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CVE-2022-3900
Cooked Pro Web Windows
9.8
CRITICAL
EPSS
4.3%
2022 1 PoC

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

CVE-2022-4305
Login as User or Customer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
83.1%
2022 1 PoC

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

CVE-2022-4447
Fontsy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.9%
2022 1 PoC

The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-3634
Contact Form 7 Database Addon Web Windows
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

CVE-2022-4383
CBX Petition for WordPress Web Database Windows
9.8
CRITICAL
EPSS
2.6%
2022 1 PoC

The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-4117
IWS Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2022 1 PoC

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

CVE-2022-4118
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop Web Database Windows
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

CVE-2022-3393
Post to CSV by BestWebSoft Web Windows
9.8
CRITICAL
EPSS
2.3%
2022 CWE-1236 1 PoC

The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection

CVE-2022-4050
JoomSport Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.2%
2022 1 PoC

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-4774
Bit Form Web Windows
9.8
CRITICAL
EPSS
8.0%
2022 1 PoC

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

CVE-2022-3463
Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms Web Windows
9.8
CRITICAL
EPSS
1.4%
2022 CWE-1236 1 PoC

The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection