1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2329
WooCommerce Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-5673
WP Mail Log Web Windows
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

CVE-2023-2068
file-manager-advanced-shortcode Web Windows
N/A
UNKNOWN
EPSS
70.4%
2023 2 PoCs

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVE-2023-4311
Vrm 360 3D Model Viewer Web Windows
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2023-0551
REST API TO MiniProgram Web Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments

CVE-2023-0219
FluentSMTP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.

CVE-2023-3182
Membership Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4970
PubyDoc Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-6272
tml-2fa Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

CVE-2023-45689
Titan MFT Windows
N/A
UNKNOWN
EPSS
0.4%
2023 CWE-22 1 PoC

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal

CVE-2023-3225
Float menu Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2803
Ultimate Addons for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-5672
WP Mail Log Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

CVE-2023-20568
Radeon™ RX 5000/6000/7000 Series Graphics Cards Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

CVE-2023-6268
JSON Content Importer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4549
DoLogin Security Web Windows
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

CVE-2023-5209
WordPress Online Booking and Scheduling Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0539
GS Insever Portfolio Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1597
tagDiv Cloud Library Web Cloud Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.