1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-3499
Photo Gallery, Images, Slider in Rbs Image Gallery Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0544
WP Login Box Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP Login Box WordPress plugin through 2.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1554
Quick Paypal Payments Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4925
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-5229
E2Pdf Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2023-6037
WP TripAdvisor Review Slider Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-7154
Hubbub Lite (formerly Grow Social) Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5343
Popup box Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2023-2009
Pretty Url Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
3.0%
2023 1 PoC

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2600
Custom Base Terms Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Custom Base Terms WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2224
SEO by 10Web Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
0.9%
2023 2 PoCs

The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2967
TinyMCE Custom Styles Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The TinyMCE Custom Styles WordPress plugin before 1.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2742
AI ChatBot Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-4388
EventON Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-6732
Ultimate Maps by Supsystic Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-1025
Simple File List Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2811
AI ChatBot Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot

CVE-2023-5980
BSK Forms Blacklist Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The BSK Forms Blacklist WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-6046
EventON Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

CVE-2023-0892
BizLibrary Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)