606 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2025-2807
Motors – Car Dealership & Classified Listings Plugin Web Windows
8.8
HIGH
EPSS
0.8%
2025 CWE-862 1 PoC

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.

CVE-2025-4954
Axle Demo Importer Web Windows
8.8
HIGH
EPSS
0.4%
2025 1 PoC

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

CVE-2025-62549
Windows 10 Version 1607 Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-822 2 PoCs

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2025-1639
Animation Addons for Elementor Pro Web Windows
8.8
HIGH
EPSS
11.1%
2025 CWE-862 1 PoC

The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins which can be leveraged to further infect a victim when Elementor is not activated on a vulnerable site.

CVE-2025-5701
HyperComments Web Windows ⚡ nuclei
8.8
HIGH
EPSS
13.4%
2025 CWE-862 2 PoCs

The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2025-3619
Chrome Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-122 1 PoC

Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVE-2025-7847
AI Engine Web Windows
8.8
HIGH
EPSS
0.6%
2025 CWE-434 1 PoC

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible.

CVE-2025-7049
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-639 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email, password, and other details of any user, including Administrator users.

CVE-2025-53778
Windows 10 Version 1507 Windows
8.8
HIGH
EPSS
1.0%
2025 CWE-287 3 PoCs

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

CVE-2025-2249
SoJ SoundSlides Web Windows
8.8
HIGH
EPSS
0.9%
2025 CWE-434 1 PoC

The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-6080
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.1%
2025 CWE-269 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.7.0. This is due to the plugin not properly validating a user's capabilities prior to adding users. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new users, including admins.

CVE-2025-11307
WP Go Maps (formerly WP Google Maps) Web Windows ⚡ nuclei
8.8
HIGH
EPSS
2.6%
2025 1 PoC

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

CVE-2025-9216
StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More Web Windows
8.8
HIGH
EPSS
0.5%
2025 CWE-434 2 PoCs

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-15386
Responsive Lightbox & Gallery Web Windows
8.8
HIGH
EPSS
0.1%
2025 1 PoC

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment with a malicious link when lightbox for comments are enabled and then approved.

CVE-2025-3671
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.2%
2025 CWE-22 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The Local File Inclusion exploit can be chained to i

CVE-2025-1930
Firefox Windows
8.8
HIGH
EPSS
0.3%
2025 1 PoC

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-1306
Newscrunch Web Windows
8.8
HIGH
EPSS
1.2%
2025 CWE-352 1 PoC

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2025-54918
Windows 10 Version 1507 Windows
8.8
HIGH
EPSS
0.2%
2025 CWE-287 1 PoC

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

CVE-2025-0366
Jupiter X Core Web Windows
8.8
HIGH
EPSS
0.6%
2025 CWE-98 1 PoC

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution. In this specific case, an attacker can create a form that allows SVG uploads, upload an SVG file with malicious content and then

CVE-2025-3054
WP User Frontend Pro Web Windows
8.8
HIGH
EPSS
1.5%
2025 CWE-434 1 PoC

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this requires the 'Private Message' module to be enabled and the Business version of the PRO software to be in use.