1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-7820
ILC Thickbox Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-2744
NextGEN Gallery Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-6857
WP MultiTasking Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-10677
BTEV Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-13420
Benaa Framework Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-94 1 PoC

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset and modify some of the plugin/theme settings. This issue was escalated to Envato over two months from the date of this disclosure and the issues, while partially patched, are still vulnerable.

CVE-2024-7892
adstxt Plugin Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-3631
HL Twitter Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack

CVE-2024-3163
Easy Property Listings Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-1319
Events Tickets Plus Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).

CVE-2024-9233
Logo Slider Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-0248
EazyDocs Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 2 PoCs

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

CVE-2024-4475
WP Logs Book Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers to make a logged in admin clear the logs them via a CSRF attack

CVE-2024-0379
Custom Twitter Feeds – A Tweets Widget or X Feed Widget Web Windows
4.3
MEDIUM
EPSS
13.9%
2024 CWE-352 1 PoC

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2024-9583
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-862 1 PoC

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the wprss_ajax_send_premium_support function in all versions up to, and including, 4.23.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send premium support requests with an attacker-controlled subject line and email address to support allowing them to impersonate the site owner. License information may also be leaked.

CVE-2024-4751
WP Prayer II Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-8157
Alphabetical List Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-13118
IP Based Login Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack

CVE-2024-12280
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack

CVE-2024-6925
TrueBooker Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-10480
3DPrint Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.