11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-25061
WP Booking System – Booking Calendar Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-79 1 PoC

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

CVE-2021-24861
Quotes Collection Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

CVE-2014-9453
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in simple-visitor-stat.php in the Simple visitor stat plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP User-Agent or (2) HTTP Referer header.

CVE-2015-9460
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2015 1 PoC

The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.

CVE-2021-24302
Hana Flv Player Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field.

CVE-2021-24788
Batch Cat Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-863 1 PoC

The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.

CVE-2021-24448
User Registration & User Profile – Profile Builder Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Modify default Redirect Delay timer' setting, allowing high privilege users to use JavaScript code in it, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-24177
File Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.

CVE-2021-25004
SEUR Oficial Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-552 1 PoC

The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.

CVE-2021-24266
The Plus Addons for Elementor Page Builder Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “The Plus Addons for Elementor Page Builder Lite” WordPress Plugin before 2.0.6 has four widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-24595
Wp Cookie Choice Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 1 PoC

The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.

CVE-2021-24648
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2015-3124
Software Genérico Windows
N/A
UNKNOWN
EPSS
58.5%
2015 1 PoC

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.

CVE-2021-24647
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.0%
2021 CWE-287 2 PoCs

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

CVE-2021-24605
Custom Post View Generator Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue

CVE-2021-24603
Site Reviews Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

CVE-2021-25020
CAOS | Host Google Analytics Locally Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-22 1 PoC

The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

CVE-2021-25077
Store Toolkit for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting

CVE-2021-24500
Workreap Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-283 2 PoCs

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.

CVE-2021-24538
Current Book Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-79 1 PoC

The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.