1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3838
WPUpper Share Buttons Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-2983
Salat Times Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3839
Analytics for WP Web Windows
4.8
MEDIUM
EPSS
0.1%
2022 1 PoC

The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3441
Rock Convert Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-4112
Quizlord Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Quizlord WordPress plugin through 2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3836
Seed Social Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-40672
CPO Shortcodes (WordPress plugin) Web Windows
4.8
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress.

CVE-2022-3237
WP Contact Slider Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-4198
WP Social Sharing Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3069
WordLift – AI powered SEO – Schema Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3420
Official Integration for Billingo Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.

CVE-2022-3631
OAuth Client by DigitialPixies Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-2658
WP Spell Check Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-3822
Donations via PayPal Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3601
Image Hover Effects Css3 Web Cloud Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3539
Testimonials Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-3469
WP Attachments Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2022-4000
WooCommerce Shipping Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The WooCommerce Shipping WordPress plugin through 1.2.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-4110
Eventify™ Web Windows
4.8
MEDIUM
EPSS
0.3%
2022 1 PoC

The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2022-3862
Livemesh Addons for Elementor Web Windows
4.8
MEDIUM
EPSS
0.2%
2022 1 PoC

The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).