1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-1593
Site Offline or Coming Soon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attack

CVE-2022-0228
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 CWE-89 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

CVE-2022-4023
3dprint Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will create an archive of any files or directories on the target server by tricking a logged in admin into submitting a form. Furthermore the created archive has a predictable location and name, allowing the attacker to download the file if they know the time at which the form was submitted, making it possible to leak sensitive files like the WordPress configuration containing database cre

CVE-2022-0867
Pricing Table Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2022 CWE-89 1 PoC

The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users

CVE-2022-1167
Careerup Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme before 2.3.1, via the filter parameters.

CVE-2022-2168
Download Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.9%
2022 CWE-79 1 PoC

The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-0874
WP Social Buttons Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2022-0728
Easy Smooth Scroll Links Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-1938
Awin Data Feed Web Windows
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-79 1 PoC

The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate analytics data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against a logged in admin viewing the plugin's settings

CVE-2022-1757
pagebar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation in some of them, it could also lead to Stored XSS issues

CVE-2022-0254
WordPress Zero Spam Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2022 CWE-89 1 PoC

The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

CVE-2022-23988
WS Form LITE – Drag & Drop Contact Form Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
14.4%
2022 CWE-79 1 PoC

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

CVE-2022-2260
GiveWP – Donation Plugin and Fundraising Platform DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-352 1 PoC

The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.

CVE-2022-1781
postTabs Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-0781
Nirweb support Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.9%
2022 CWE-89 1 PoC

The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

CVE-2022-0478
Event Manager and Tickets Selling Plugin for WooCommerce Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-89 1 PoC

The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks

CVE-2022-0633
UpdraftPlus WordPress Backup Plugin (Free) Web Windows
N/A
UNKNOWN
EPSS
1.4%
2022 CWE-863 2 PoCs

The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent site & database backup.

CVE-2022-2372
YaySMTP – Simple WP SMTP Mail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-0163
Smart Forms – when you need more than just a contact form Web Windows
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-862 1 PoC

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.

CVE-2022-1645
Amazon Link Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.