1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-0904
Fancy Product Designer Web Windows
5.9
MEDIUM
EPSS
0.4%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9796
WP-Advanced-Search Web Database Windows ⚡ nuclei
5.9
MEDIUM
EPSS
83.1%
2024 5 PoCs

The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2024-3753
Hostel Web Windows ⚡ nuclei
5.9
MEDIUM
EPSS
1.5%
2024 1 PoC

The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5442
Photo Gallery, Sliders, Proofing and Themes Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2375
WPQA Builder Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-6231
Request a Quote Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-10472
Stylish Price List Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-2403
Remote Desktop Manager Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory.

CVE-2024-4096
Responsive Tabs Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks

CVE-2024-2749
VikBooking Hotel Booking Engine & PMS Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.

CVE-2024-9836
RSS Feed Widget Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-3964
Product Enquiry for WooCommerce Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-5573
Easy Table of Contents Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-10104
Jobs for WordPress Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

CVE-2024-4753
WP Secure Maintenance Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2605
Firefox Web Windows
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-5033
SULly Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-1905
Smart Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-9156
TI WooCommerce Wishlist Web Database Windows
5.9
MEDIUM
EPSS
0.6%
2024 1 PoC

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-10309
Tracking Code Manager Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.