1466 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-6925
TrueBooker Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-10480
3DPrint Lite Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2024-9756
Order Attachments for WooCommerce Web Windows
4.3
MEDIUM
EPSS
4.1%
2024 CWE-862 1 PoC

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

CVE-2024-1279
Paid Memberships Pro Web Windows
4.3
MEDIUM
EPSS
0.5%
2024 1 PoC

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.

CVE-2024-23493
Mattermost Windows
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 

CVE-2024-11842
DN Shipping by Weight for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-1564
wp-schema-pro Web Windows
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

CVE-2024-2908
Call Now Button Web Windows
4.3
MEDIUM
EPSS
2.5%
2024 1 PoC

The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9889
ElementInvader Addons for Elementor Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected posts, pages, and Elementor templates that they should not have access to.

CVE-2024-7984
Joy Of Text Lite Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-4382
CB (legacy) Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

CVE-2024-2429
Salon booking system Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12709
Bulk Me Now! Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-6860
WP MultiTasking Web Windows
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack

CVE-2024-1330
kadence-blocks-pro Web Windows
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

CVE-2024-13580
XV Random Quotes Web Windows
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

CVE-2024-13208
Maps Plugin using Google Maps for WordPress Web Windows
4.3
MEDIUM
EPSS
0.0%
2024 1 PoC

The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-9926
Jetpack Web Windows
4.3
MEDIUM
EPSS
22.8%
2024 1 PoC

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form

CVE-2024-38143
Windows 11 Version 24H2 Windows
4.2
MEDIUM
EPSS
4.3%
2024 CWE-306 1 PoC

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

CVE-2024-10815
PostLists Web Windows
4.2
MEDIUM
EPSS
0.2%
2024 1 PoC

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers