11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2024-13618
aoa-downloadable Web Windows
7.2
HIGH
EPSS
0.2%
2024 1 PoC

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

CVE-2024-8625
TS Poll Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
2.9%
2024 1 PoC

The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2021-24151
WP Editor Web Database Windows
7.2
HIGH
EPSS
0.5%
2021 1 PoC

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

CVE-2024-24693
Zoom Rooms Client for Windows Windows
7.2
HIGH
EPSS
0.1%
2024 CWE-379 1 PoC

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

CVE-2024-7766
Adicon Server Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2022-3394
WP All Export Pro Web Windows
7.2
HIGH
EPSS
1.3%
2022 CWE-94 1 PoC

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVE-2024-10499
AI Engine Web Database Windows
7.2
HIGH
EPSS
0.4%
2024 1 PoC

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-11269
AHAthat Plugin Web Database Windows
7.2
HIGH
EPSS
0.3%
2024 1 PoC

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.

CVE-2022-4489
HUSKY Web Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2024-5807
Business Card Web Windows
7.2
HIGH
EPSS
0.7%
2024 1 PoC

The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.

CVE-2024-9504
Booking calendar, Appointment Booking System Web Windows
7.2
HIGH
EPSS
0.7%
2024 CWE-434 1 PoC

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

CVE-2021-39352
Catch Themes Demo Import Web Windows
7.2
HIGH
EPSS
75.6%
2021 CWE-434 3 PoCs

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.

CVE-2022-3366
PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2 unserializes the content of imported files, which could lead to PHP object injection attacks by administrators, on multisite WordPress configurations. Successful exploitation in this case requires other plugins with a suitable gadget chain to be present on the site.

CVE-2024-5902
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Web Windows
7.2
HIGH
EPSS
3.5%
2024 CWE-79 1 PoC

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in feedback form responses that will execute whenever a high-privileged user tries to view them.

CVE-2021-24786
Download Monitor Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
2.2%
2021 CWE-89 1 PoC

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

CVE-2024-9022
TS Poll – Survey, Versus Poll, Image Poll, Video Poll Web Database Windows
7.2
HIGH
EPSS
1.6%
2024 CWE-89 1 PoC

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2022-4323
Analyticator Web Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

CVE-2025-0514
LibreOffice Windows
7.2
HIGH
EPSS
0.2%
2025 CWE-20 1 PoC

Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.

CVE-2022-3334
Easy WP SMTP Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2025-10686
Creta Testimonial Showcase Web Windows
7.2
HIGH
EPSS
0.1%
2025 1 PoC

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.