Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 601-620 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24446 - Before 1 Plugin

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation

PLUGIN Before 1

CVE-2021-24446

MEDIUM CVSS 5.4 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-24904 - Before 1 Plugin

The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24904

MEDIUM CVSS 4.8 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25014 - Before 1 Plugin

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-25014

LOW CVSS 3.5 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2021-25029 - Before 1 Plugin

The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-25029

MEDIUM CVSS 4.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25004 - Before 1 Plugin

The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.

PLUGIN Before 1

CVE-2021-25004

MEDIUM CVSS 4.9 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2022-0220 - Before 1 Plugin

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)

PLUGIN Before 1

CVE-2022-0220

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25089 - Before 1 Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore parameter before outputting it back in the Restore page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-25089

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25085 - Before 1 Plugin

The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-25085

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24983 - Before 1 Plugin

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sent to the wpassetcleanup_fetch_active_plugins_icons AJAX action (available to admin users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24983

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24762 - Before 1 Plugin

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

PLUGIN Before 1

CVE-2021-24762

CRITICAL CVSS 9.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24814 - Before 1 Plugin

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same…

PLUGIN Before 1

CVE-2021-24814

CRITICAL CVSS 9.6 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24763 - Before 1 Plugin

The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could also lead to a Stored Cross-Site Scripting issue which will be executed in the context of a user viewing any survey

PLUGIN Before 1

CVE-2021-24763

HIGH CVSS 8.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24761 - Before 1 Plugin

The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

PLUGIN Before 1

CVE-2021-24761

MEDIUM CVSS 6.5 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24937 - Before 1 Plugin

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24937

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24926 - Before 1 Plugin

The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24926

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24764 - Before 1 Plugin

The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[session_id] of single_statistics page, type and message of importexport page) before outputting them back in pages/attributes in the admin dashboard, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-24764

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24775 - Before 1 Plugin

The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.

PLUGIN Before 1

CVE-2021-24775

MEDIUM CVSS 5.3 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24868 - Before 1 Plugin

The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.

PLUGIN Before 1

CVE-2021-24868

MEDIUM CVSS 4.3 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25073 - Before 1 Plugin

The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Before 1

CVE-2021-25073

HIGH CVSS 8.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25045 - Before 1 Plugin

The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue

PLUGIN Before 1

CVE-2021-25045

HIGH CVSS 7.2 2022-01-24
Scroll to top