Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 621-640 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-25013 - Before 1 Plugin

The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts

PLUGIN Before 1

CVE-2021-25013

MEDIUM CVSS 6.5 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24989 - Before 1 Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog

PLUGIN Before 1

CVE-2021-24989

MEDIUM CVSS 6.5 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25080 - Before 1 Plugin

The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry

PLUGIN Before 1

CVE-2021-25080

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25079 - Before 1 Plugin

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

PLUGIN Before 1

CVE-2021-25079

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25062 - Before 1 Plugin

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-25062

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25035 - Before 1 Plugin

The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-25035

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25017 - Before 1 Plugin

The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-25017

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25049 - Before 1 Plugin

The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-25049

MEDIUM CVSS 4.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24858 - Before 1 Plugin

The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

PLUGIN Before 1

CVE-2021-24858

HIGH CVSS 7.2 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24423 - Before 1 Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24423

MEDIUM CVSS 4.8 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24733 - Before 1 Plugin

The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.

PLUGIN Before 1

CVE-2021-24733

MEDIUM CVSS 4.3 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25024 - Before 1 Plugin

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

PLUGIN Before 1

CVE-2021-25024

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-24909 - Before 1 Plugin

The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the includes/acf_photo_gallery_metabox_edit.php file before outputing back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24909

MEDIUM CVSS 6.1 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25005 - Before 1 Plugin

The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-25005

MEDIUM CVSS 4.8 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25025 - Before 1 Plugin

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

PLUGIN Before 1

CVE-2021-25025

MEDIUM CVSS 4.3 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25047 - Before 1 Plugin

The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users

PLUGIN Before 1

CVE-2021-25047

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25043 - Before 1 Plugin

The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-25043

MEDIUM CVSS 6.1 2022-01-10
Threat Entry Updated 2025-05-22

CVE-2021-25022 - Before 1 Plugin

The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestamp and job_id parameter before outputting then back in admin pages, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-25022

MEDIUM CVSS 6.1 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24831 - Before 1 Plugin

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

PLUGIN Before 1

CVE-2021-24831

HIGH CVSS 7.5 2022-01-03
Scroll to top