1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-1221
Gwyn's Imagemap Selector Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2022 CWE-79 1 PoC

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

CVE-2022-2754
Ketchup Restaurant Reservations Web Database Windows
N/A
UNKNOWN
EPSS
4.4%
2022 CWE-89 1 PoC

The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

CVE-2022-0229
miniOrange's Google Authenticator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.

CVE-2022-1303
Slide Anything – Responsive Content / HTML Slider and Carousel Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow high privilege users such as editor and above to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2022-1392
Videos sync PDF Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2022 CWE-22 2 PoCs

The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

CVE-2022-2172
LinkWorth Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.

CVE-2022-1697
Okta Active Directory Agent Windows
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.

CVE-2022-1772
Google Places Reviews Web Windows
N/A
UNKNOWN
EPSS
2.5%
2022 CWE-79 1 PoC

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVE-2022-2538
WP Hide & Security Enhancer Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting

CVE-2022-0418
Event List Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed

CVE-2022-2737
WP STAGING – Backup Duplicator & Migration Web Windows
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-79 1 PoC

The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2022-1251
Ask me Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-352 1 PoC

The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.

CVE-2022-1386
Fusion Builder Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 CWE-918 9 PoCs

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVE-2022-0448
CP Blocks Web Windows
N/A
UNKNOWN
EPSS
6.3%
2022 CWE-79 1 PoC

The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

CVE-2022-0674
Kunze Law Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-79 1 PoC

The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2022-0770
Translate WordPress with GTranslate Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-352 1 PoC

The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or page

CVE-2022-1614
WP-EMail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.

CVE-2022-2083
Simple Single Sign On Web Windows
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.

CVE-2022-1112
Autolinks Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-79 1 PoC

The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack

CVE-2022-2151
Best Contact Management Software for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.