1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-1573
HTML2WP Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them

CVE-2022-2373
Simply Schedule Appointments – WordPress Booking Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2022 CWE-862 1 PoC

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address

CVE-2022-1255
Import and export users and customers Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues

CVE-2022-1904
Pricing Tables WordPress Plugin – Easy Pricing Tables Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2022 CWE-79 1 PoC

The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputting it back in a page available to any user (both authenticated and unauthenticated) when a specific setting is enabled, leading to a Reflected Cross-Site Scripting

CVE-2022-1320
Sliderby10Web Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2022-2655
Classified Listing Pro - Classified ads & Business Directory Plugin Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2022-0377
LearnPress Web Windows
N/A
UNKNOWN
EPSS
3.0%
2022 1 PoC

Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of this request, the name of the user-supplied image is changed with a MD5 value. This process can be conducted only when type of the image is JPG or PNG. An attacker can use this vulnerability in order to rename an arbitrary image file. By doing this, they could destroy the design o

CVE-2022-2369
YaySMTP – Simple WP SMTP Mail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-862 1 PoC

The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin

CVE-2022-1594
HC Custom WP-Admin URL Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL

CVE-2022-27984
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
20.1%
2022 0 PoCs

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-4125
Popup Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well

CVE-2022-2377
Directorist – WordPress Business Directory Plugin with Classified Ads Listings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-862 1 PoC

The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog

CVE-2022-2374
Simply Schedule Appointments – WordPress Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1791
One Click Plugin Updater Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check.

CVE-2022-2215
GiveWP – Donation Plugin and Fundraising Platform Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0760
Simple Link Directory Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.3%
2022 CWE-89 1 PoC

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection

CVE-2022-1037
EXMAGE – WordPress Image Links Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-918 1 PoC

The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs

CVE-2022-2099
WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

CVE-2022-0595
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVE-2022-2411
Auto More Tag Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)