1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-4200
Login with Cognito Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4299
Metricool Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Metricool WordPress plugin before 1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3840
Login for Google Apps Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3139
We’re Open! Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4442
Custom Post Types and Custom Fields creator Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Custom Post Types and Custom Fields creator WordPress plugin before 2.3.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-3824
WP Admin UI Customize Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3936
Team Members Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup).

CVE-2022-3832
External Media Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-2574
Meks Easy Social Share Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3070
Generate PDF using Contact Form 7 Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3855
404 to Start Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3350
Contact Bank – Contact Form Builder for WordPress Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-23179
Contact Form & Lead Form Elementor Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-3610
Jeeng Push Notifications Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3909
Add Comments Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4260
WP-Ban Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
1.0%
2022 1 PoC

The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3919
Jetpack CRM Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3837
Uji Countdown Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Uji Countdown WordPress plugin before 2.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3829
Font Awesome 4 Menus Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4119
Image Optimizer, Resizer and CDN Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).