1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-5087
Page Builder: Pagelayer Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.7.8 doesn't prevent attackers with author privileges and higher from inserting malicious JavaScript inside a post's header or footer code.

CVE-2023-4783
Magee Shortcodes Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Magee Shortcodes WordPress plugin through 2.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0424
MS-Reviews Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks

CVE-2023-0526
Post Shortcode Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0552
Registration Forms Web Windows ⚡ nuclei
5.4
MEDIUM
EPSS
16.4%
2023 1 PoC

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

CVE-2023-0174
WP VR Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0169
Form plugin for WordPress Web Windows
5.4
MEDIUM
EPSS
1.3%
2023 1 PoC

The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2751
Upload Resume Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.

CVE-2023-6592
FastDup Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
4.4%
2023 2 PoCs

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-4631
DoLogin Security Web Windows
5.3
MEDIUM
EPSS
1.7%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

CVE-2023-46666
Elastic Sharepoint Online Python Connector Database Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

CVE-2023-51062
Software Genérico Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.

CVE-2023-6334
Workforce Access Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: before 8.7.

CVE-2023-7252
Tickera Web Windows
5.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.

CVE-2023-45503
Software Genérico Web Database Windows
5.3
MEDIUM
EPSS
1.8%
2023 1 PoC

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.

CVE-2023-7232
Backup and Restore WordPress Web Windows
5.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data

CVE-2023-6155
Quiz Maker Web Windows
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email addresses.

CVE-2023-6447
EventPrime Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

CVE-2023-4281
Activity Log Web Windows
5.3
MEDIUM
EPSS
1.5%
2023 2 PoCs

This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

CVE-2023-22622
Software Genérico Web Windows
5.3
MEDIUM
EPSS
8.4%
2023 3 PoCs

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.