1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13431
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin Web Windows
6.1
MEDIUM
EPSS
1.3%
2024 CWE-79 1 PoC

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in all versions up to, and including, 1.6.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVE-2024-9651
Fluent Forms Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5729
Simple AL Slider Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-4272
Support SVG Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-3692
Gutenverse Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-10703
Registrations for the Events Calendar Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11607
GTPayment Donations Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-12723
Infility Global Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-6017
Music Request Manager Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-2857
Simple Buttons Creator Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.

CVE-2024-11141
Sailthru Triggermail Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13328
Giga Messenger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-12873
Custom Field Manager Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-25976
HAWKI Web Windows
6.1
MEDIUM
EPSS
0.5%
2024 CWE-79 2 PoCs

When LDAP authentication is activated in the configuration it is possible to obtain reflected XSS execution by creating a custom URL that the victim only needs to open in order to execute arbitrary JavaScript code in the victim's browser. This is due to a fault in the file login.php where the content of "$_SERVER['PHP_SELF']" is reflected into the HTML of the website. Hence the attacker does not need a valid account in order to exploit this issue.

CVE-2024-9934
Wp-ImageZoom Web Windows
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-10679
Quiz and Survey Master (QSM) Web Windows
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5809
WP Ajax Contact Form Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users

CVE-2024-11273
Contact Form & SMTP Plugin for WordPress by PirateForms Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13218
Fast Tube Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Fast Tube WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-8386
Firefox Windows
6.1
MEDIUM
EPSS
0.3%
2024 2 PoCs

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.