1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13383
HD Quiz Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-3282
WP Table Builder Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6498
Chatbot for WordPress by Collect.chat ⚡️ Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-13493
Sensly Online Presence Web Windows
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9641
LuckyWP Table of Contents Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10939
Image Widget Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-5799
CM Pop-Up Banners for WordPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

CVE-2024-9882
Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8702
Backup Database Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-8618
Page Builder: Pagelayer Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-10706
Download Manager Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9883
Pods Web Windows
4.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4664
WP Chat App Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

CVE-2024-8619
Ajax Search Lite Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The Ajax Search Lite WordPress plugin before 4.12.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9768
Formidable Forms Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13610
Simple Social Media Share Buttons Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13382
Calculated Fields Form Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-13616
VikBooking Hotel Booking Engine & PMS Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11843
Panorama Web Windows
4.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7769
ClickSold IDX Web Windows
4.8
MEDIUM
EPSS
0.0%
2024 1 PoC

The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).