1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-4505
Staff/Employee Business Directory for Active Directory Web Windows
2.2
LOW
EPSS
0.4%
2023 CWE-306 1 PoC

The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

CVE-2023-4506
Active Directory Integration / LDAP Integration Web Windows
2.2
LOW
EPSS
0.4%
2023 CWE-306 1 PoC

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

CVE-2023-0194
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
2.0
LOW
EPSS
0.1%
2023 CWE-1284 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an invalid display configuration may lead to denial of service.

CVE-2023-0195
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
2.0
LOW
EPSS
0.1%
2023 CWE-1284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver

CVE-2023-0630
Slimstat Analytics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2023 2 PoCs

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

CVE-2023-2579
InventoryPress Web Windows
N/A
UNKNOWN
EPSS
16.6%
2023 1 PoC

The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1110
Yellow Yard Searchbar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-5559
10Web Booster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
52.5%
2023 1 PoC

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

CVE-2023-0364
real.Kit Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5652
WP Hotel Booking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.6%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

CVE-2023-0439
NEX-Forms Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.

CVE-2023-2568
Photo Gallery by Ays Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0073
Client Logo Carousel Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0631
Paid Memberships Pro Web Database Windows
N/A
UNKNOWN
EPSS
74.0%
2023 1 PoC

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

CVE-2023-5119
Forminator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Forminator WordPress plugin before 1.27.0 does not properly sanitize the redirect-url field in the form submission settings, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVE-2023-5874
Popup box Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4252
EventPrime Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.

CVE-2023-51750
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules."

CVE-2023-0159
Extensive VC Addons for WPBakery page builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2023 1 PoC

The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

CVE-2023-2529
Enable SVG Uploads Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Enable SVG Uploads WordPress plugin through 2.1.5 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.