1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-1207
Booking Calendar Web Database Windows
9.8
CRITICAL
EPSS
78.7%
2024 CWE-89 1 PoC

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-10924
Really Simple Security Pro multisite Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-288 16 PoCs

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

CVE-2024-8943
LatePoint Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
40.1%
2024 CWE-288 0 PoCs

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. Note that logging in as a WordPress user is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability is partially patched in version 5.0.12 and fully patch

CVE-2024-9822
Pedalo Connector Web Windows
9.8
CRITICAL
EPSS
14.6%
2024 CWE-288 1 PoC

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.

CVE-2024-9932
Wux Blog Editor Web Windows
9.8
CRITICAL
EPSS
75.4%
2024 CWE-434 2 PoCs

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-12877
GiveWP – Donation Plugin and Fundraising Platform Web Windows
9.8
CRITICAL
EPSS
27.5%
2024 CWE-502 2 PoCs

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input from the donation form like 'firstName'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files on the server that makes remote code execution possible. Please note this was only partially patched in 3.19.3, a fully sufficient patch was not released until 3.19.4. However, another CVE was assigned b

CVE-2024-4620
ARForms - Premium WordPress Form Builder Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
72.4%
2024 1 PoC

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

CVE-2024-6924
TrueBooker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.5%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-5765
WpStickyBar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
78.2%
2024 1 PoC

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2024-10508
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Web Windows
9.8
CRITICAL
EPSS
15.3%
2024 CWE-230 3 PoCs

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.

CVE-2024-8353
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.6%
2024 CWE-502 3 PoCs

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows th

CVE-2024-2876
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2024 CWE-89 7 PoCs

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-8275
The Events Calendar Web Database Windows
9.8
CRITICAL
EPSS
83.5%
2024 CWE-89 3 PoCs

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Only sites that have manually added tribe_has_next_event() will be vulnerable to this SQL injection.

CVE-2024-6220
简数采集器 Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.6%
2024 CWE-434 0 PoCs

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-8289
MultiVendorX – WooCommerce Multivendor Marketplace Solutions Web Windows
9.8
CRITICAL
EPSS
10.1%
2024 CWE-862 1 PoC

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability check on the update_item_permissions_check and create_item_permissions_check functions in all versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to change the password of any user with the vendor role, create new users with the vendor role, and demote other users like administrators to the vendor role.

CVE-2024-4577
🔥 KEV PHP Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-78 85 PoCs

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVE-2024-6164
Filter & Grids Web Windows
9.8
CRITICAL
EPSS
5.3%
2024 1 PoC

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-6624
JSON API User Web Windows
9.8
CRITICAL
EPSS
43.5%
2024 CWE-269 2 PoCs

The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

CVE-2024-6459
News Element Elementor Blog Magazine Web Windows
9.8
CRITICAL
EPSS
5.8%
2024 1 PoC

The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-11635
Iptanus File Upload Web Windows
9.8
CRITICAL
EPSS
23.7%
2024 CWE-94 1 PoC

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.