1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-5575
Ditty Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-6879
Quiz and Survey Master (QSM) Web Windows
4.7
MEDIUM
EPSS
0.3%
2024 1 PoC

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or post where the Quiz is embedded, which could allows contributor and above roles to perform Stored Cross-Site Scripting (XSS) attacks.

CVE-2024-1712
Carousel Slider Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3941
reCAPTCHA Jetpack Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-11223
WPForms Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9770
WP-Recall Web Database Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-6073
wp-cart-for-digital-products Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-7689
Snapshot Backup Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-5280
wp-affiliate-platform Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

CVE-2024-3265
Advanced Search Web Database Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making it possible for users with the administrator role to conduct SQL Injection attacks in the context of a multisite WordPress configurations.

CVE-2024-2262
Themify Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

CVE-2024-2428
The Ultimate Video Player For WordPress Web Windows
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS attacks

CVE-2024-4217
shortcodes-ultimate-pro Web Windows
4.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.

CVE-2024-3993
AZAN Plugin Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-13126
Download Manager Web Windows ⚡ nuclei
4.6
MEDIUM
EPSS
1.5%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

CVE-2024-3919
OpenPGP Form Encryption for WordPress Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-2218
LuckyWP Table of Contents Web Windows
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-4271
SVGator Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-6362
Ultimate Blocks Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-13096
WP Finance Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.