1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-50959
Contact Form Builder Web Windows
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.

CVE-2022-50949
Videos sync PDF Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options panel to execute arbitrary JavaScript when administrators view or edit video settings.

CVE-2022-50945
real-time web stats Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress 3dady real-time web stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin options panel to execute arbitrary code when the page is viewed.

CVE-2022-50960
International Sms For Contact Form Web Windows
5.1
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

WordPress International Sms For Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers.

CVE-2022-50958
Jetpack Web Windows
5.1
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

WordPress Plugin Jetpack 9.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the post_id parameter. Attackers can craft URLs to the grunion-form-view.php endpoint with script payloads in the post_id parameter to execute arbitrary JavaScript in victim browsers.

CVE-2022-4157
Contest Gallery Web Database Windows
4.9
MEDIUM
EPSS
0.8%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVE-2022-43959
Software Genérico Web Windows
4.9
MEDIUM
EPSS
1.1%
2022 1 PoC

Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.

CVE-2022-4108
Wholesale Market for WooCommerce Web Windows
4.9
MEDIUM
EPSS
0.6%
2022 1 PoC

The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite)

CVE-2022-2926
Download Manager Web Windows
4.9
MEDIUM
EPSS
2.7%
2022 CWE-22 1 PoC

The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory

CVE-2022-4154
Contest Gallery Pro Web Database Windows
4.9
MEDIUM
EPSS
0.8%
2022 2 PoCs

The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVE-2022-4155
Contest Gallery Web Database Windows
4.9
MEDIUM
EPSS
1.3%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.

CVE-2022-1094
amr users Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3408
WP Word Count Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2022-4242
WP Google Review Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3753
Evaluate Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-3392
WP Humans.txt Web Windows
4.8
MEDIUM
EPSS
0.6%
2022 CWE-79 1 PoC

The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3609
GetYourGuide Ticketing Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4200
Login with Cognito Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3831
reCAPTCHA Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3830
WP Page Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).