1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-5651
WP Hotel Booking Web Windows
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts

CVE-2023-0095
Page View Count Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0660
Smart Slider 3 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0094
UpQode Google Maps Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3372
Lana Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2414
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to modify the plugins settings, upload arbitrary files, and inject malicious JavaScript (before 4.3.2).

CVE-2023-0252
Contextual Related Posts Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0282
YourChannel: Everything you want in a YouTube plugin. Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

CVE-2023-28664
Meta Data and Taxonomies Filter WordPress Plugin Web Windows
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticated user.

CVE-2023-0376
Qubely Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0362
Themify Portfolio Post Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0399
Image Over Image For WPBakery Page Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0074
WP Social Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0379
Spotlight Social Feeds [Block, Shortcode, and Widget] Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0372
EmbedStories Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-1905
WP Popups Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003

CVE-2023-0542
Custom Post Type List Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-7084
Voting Record Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS attacks

CVE-2023-4805
Tutor LMS Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6485
Html5 Video Player Web Windows
5.4
MEDIUM
EPSS
1.9%
2023 1 PoC

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users like admins