1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-0623
VK Block Patterns Web Windows
4.3
MEDIUM
EPSS
4.1%
2024 CWE-352 1 PoC

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to missing or incorrect nonce validation on the vbp_clear_patterns_cache() function. This makes it possible for unauthenticated attackers to clear the patterns cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-8082
Widgets Reset Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-3477
Popup Box Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks

CVE-2024-3545
Server Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining access to a computer where the software is installed even though the offline mode is disabled.

CVE-2024-11672
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

CVE-2024-4474
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
2.8%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-4969
Widget Bundle Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack

CVE-2024-13306
Maps Plugin using Google Maps for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-4875
HT Mega Addons for Elementor – Elementor Widgets & Template Builder Web Windows
4.3
MEDIUM
EPSS
3.8%
2024 CWE-862 1 PoC

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update options such as users_can_register, which can lead to unauthorized user registration.

CVE-2024-5169
Video Widget Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0902
Fancy Product Designer Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-1745
Testimonial Slider Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them.

CVE-2024-4957
Frontend Checklist Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-0588
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Web Windows
4.3
MEDIUM
EPSS
9.3%
2024 CWE-352 1 PoC

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible for unauthenticated attackers to enable the streamline setting with Lifter LMS via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2024-32793 and CVE-2024-32794 appear to be a duplicate of this issue.

CVE-2024-5808
WP Ajax Contact Form Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-8050
Custom Author Base Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-11373
Connexion Logs Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-8398
Simple Nav Archives Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1204
Meta Box Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.

CVE-2024-4477
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting