1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-4443
Business Directory Plugin – Easy Listing Directories for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2024 CWE-89 1 PoC

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-6809
Simple Video Directory Web Database Windows
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-30080
Windows 10 Version 1809 Windows
9.8
CRITICAL
EPSS
16.7%
2024 CWE-416 2 PoCs

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2024-9707
Hunk Companion Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2024 CWE-862 2 PoCs

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

CVE-2024-10571
Chartify – WordPress Chart Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
87.3%
2024 CWE-98 2 PoCs

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-9822
Pedalo Connector Web Windows
9.8
CRITICAL
EPSS
14.6%
2024 CWE-288 1 PoC

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.

CVE-2024-1981
Migration, Backup, Staging – WPvivid Web Database Windows
9.8
CRITICAL
EPSS
2.6%
2024 1 PoC

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-11613
Iptanus File Upload Web Windows
9.8
CRITICAL
EPSS
75.1%
2024 CWE-94 2 PoCs

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.

CVE-2024-4295
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2024 CWE-89 3 PoCs

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-8277
WooCommerce Photo Reviews Premium Web Windows
9.8
CRITICAL
EPSS
52.1%
2024 CWE-288 1 PoC

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly verifying the user's identity. This makes it possible for unauthenticated attackers to log in as user that has dismissed an admin notice in the past 30 days, which is often an administrator. Alternatively, a user can log in as any user with any transient that has a valid user_id as the value, though it would be more difficult t

CVE-2024-8425
WooCommerce Ultimate Gift Card Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
42.7%
2024 CWE-434 2 PoCs

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this may have been patched on an older version than 2.9.2, however, we do not have access to older versions of the software to confirm when the patch was added.

CVE-2024-6928
Opti Marketing Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.5%
2024 1 PoC

The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2024-9659
School Management System for Wordpress Web Windows
9.8
CRITICAL
EPSS
19.9%
2024 CWE-434 1 PoC

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-8943
LatePoint Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
40.1%
2024 CWE-288 0 PoCs

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being supplied during the booking customer step. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. Note that logging in as a WordPress user is only possible if the "Use WordPress users as customers" setting is enabled, which is disabled by default. The vulnerability is partially patched in version 5.0.12 and fully patch

CVE-2024-8353
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.6%
2024 CWE-502 3 PoCs

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files and achieve remote code execution. This is essentially the same vulnerability as CVE-2024-5932, however, it was discovered the the presence of stripslashes_deep on user_info allows th

CVE-2024-11281
WooCommerce Point of Sale Web Windows
9.8
CRITICAL
EPSS
3.1%
2024 CWE-862 1 PoC

The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. This makes it possible for unauthenticated attackers to change the email of arbitrary user accounts, including administrators, and reset their password to gain access to the account.

CVE-2024-8856
Backup and Staging by WP Time Capsule Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2024 CWE-434 4 PoCs

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-1698
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2024 CWE-89 5 PoCs

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-4898
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.1%
2024 CWE-862 3 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to InstaWP API, edit arbitrary site options and create administrator accounts.

CVE-2024-1207
Booking Calendar Web Database Windows
9.8
CRITICAL
EPSS
78.7%
2024 CWE-89 1 PoC

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.