1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-2710
Scroll To Top Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1686
Five Minute Webshop Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-89 2 PoCs

The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in a SQL statement when editing a product via the admin dashboard, leading to an SQL Injection

CVE-2022-0840
Easy Social Icons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new social icon, allowing high privileged users to inject arbitrary javascript even when the unfiltered_html capability is disallowed.

CVE-2022-1104
Popup Maker – Popup for opt-ins, lead gen, & more Web Windows
N/A
UNKNOWN
EPSS
13.5%
2022 CWE-79 1 PoC

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-2391
Inspiro PRO Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.

CVE-2022-0879
Caldera Forms – More Than Contact Forms Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2022 CWE-79 1 PoC

The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVE-2022-1913
Add Post URL Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-1093
WP Meta SEO Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.

CVE-2022-0648
Team Circle Image Slider With Lightbox Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

CVE-2022-1777
Filr – Secure document library Web Windows
N/A
UNKNOWN
EPSS
0.8%
2022 CWE-862 1 PoC

The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow them to upload arbitrary HTML files as well as delete all files or arbitrary ones.

CVE-2022-0147
Cookie Information | Free GDPR Consent Solution Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2022 CWE-79 1 PoC

The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVE-2022-0479
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.4%
2022 CWE-89 1 PoC

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

CVE-2022-1960
MyCSS Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2022-0814
Ubigeo de Perú para Woocommerce y WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
58.2%
2022 CWE-89 1 PoC

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

CVE-2022-0250
Redirection for Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2022 CWE-79 1 PoC

The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2022-1604
MailerLite – Signup forms (official) Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2022-3142
NEX-Forms – Ultimate Form Builder – Contact forms and much more Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2022 CWE-89 3 PoCs

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings.

CVE-2022-1764
WP-chgFontSize Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2022-2863
Migration, Backup, Staging – WPvivid Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2022 CWE-22 2 PoCs

The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack

CVE-2022-2537
WooCommerce PDF Invoices & Packing Slips Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.