1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-2623
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

CVE-2023-5458
CITS Support svg, webp Media and TTF,OTF File Upload Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-6077
Slider Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected

CVE-2023-0873
Kanban Boards for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5605
URL Shortify Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0419
Shortcode for Font Awesome Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3076
MStore API Web Windows
N/A
UNKNOWN
EPSS
30.4%
2023 1 PoC

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

CVE-2023-2627
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

CVE-2023-2877
Formidable Forms Web Windows
N/A
UNKNOWN
EPSS
70.0%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

CVE-2023-3219
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.0%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

CVE-2023-2813
Aapna Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop

CVE-2023-0365
React Webcam Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-5348
Product Catalog Mode For WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.

CVE-2023-3650
Bubble Menu Web Windows
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-5108
Easy Newsletter Signups Web Database Windows
N/A
UNKNOWN
EPSS
1.3%
2023 1 PoC

The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0210
Linux Kernel Windows
N/A
UNKNOWN
EPSS
0.6%
2023 CWE-122 3 PoCs

A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.

CVE-2023-4642
kk Star Ratings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

CVE-2023-2482
Responsive CSS EDITOR Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.

CVE-2023-2744
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Database Windows
N/A
UNKNOWN
EPSS
28.4%
2023 3 PoCs

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-0063
WordPress Shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.