11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-1912
Limit Login Attempts Web Windows
7.2
HIGH
EPSS
5.3%
2023 CWE-79 2 PoCs

The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses the plugin's settings page. This only works when the plugin prioritizes use of the X-FORWARDED-FOR header, which can be configured in its settings.

CVE-2023-0329
Elementor Website Builder Web Database Windows
7.2
HIGH
EPSS
9.1%
2023 2 PoCs

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

CVE-2023-7027
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Web Windows
7.2
HIGH
EPSS
0.8%
2023 CWE-79 1 PoC

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ header in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-3388
Beautiful Cookie Consent Banner Web Windows ⚡ nuclei
7.2
HIGH
EPSS
68.7%
2023 CWE-79 0 PoCs

The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A partial patch was made available in 2.10.1 and the issue was fully patched in 2.10.2.

CVE-2023-1408
Video List Manager Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
12.4%
2023 1 PoC

The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-4268
Plugin Logic Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2024-6354
Remote Desktop Manager Windows
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

CVE-2023-1669
SEOPress Web Windows
7.2
HIGH
EPSS
6.4%
2023 1 PoC

The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-5957
Ni Purchase Order(PO) For WooCommerce Web Windows
7.2
HIGH
EPSS
0.6%
2023 1 PoC

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

CVE-2023-6222
Quttera Web Malware Scanner Web Windows
7.2
HIGH
EPSS
0.4%
2023 2 PoCs

IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks

CVE-2022-3300
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Web Database Windows
7.2
HIGH
EPSS
0.8%
2022 CWE-89 1 PoC

The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-3689
HTML Forms Web Database Windows
7.2
HIGH
EPSS
40.3%
2022 3 PoCs

The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-3131
Search Logger – Know What Your Visitors Search Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

CVE-2022-3380
Customizer Export/Import Web Windows
7.2
HIGH
EPSS
1.0%
2022 CWE-502 1 PoC

The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lead to PHP object injection issues when an admin imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-4358
WP RSS By Publishers Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2025-5961
WPvivid — Backup, Migration & Staging Web Windows ⚡ nuclei
7.2
HIGH
EPSS
2.0%
2025 CWE-434 3 PoCs

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: Uploaded files are only accessible on WordPress instances running on the NGINX web server as the existing .htaccess within the target file upload

CVE-2022-4373
Quote-O-Matic Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The Quote-O-Matic WordPress plugin through 1.0.5 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-4238
Prevent files / folders access Web Windows
7.2
HIGH
EPSS
24.7%
2023 2 PoCs

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

CVE-2020-5741
🔥 KEV Plex Media Server (Windows) Windows
7.2
HIGH
EPSS
35.2%
2020 2 PoCs

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

CVE-2023-2655
Contact Form by WD Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin