Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 641-660 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24828 - Before 1 Plugin

The Mortgage Calculator / Loan Calculator WordPress plugin before 1.5.17 does not escape the some of the attributes of its mlcalc shortcode before outputting them, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2021-24828

MEDIUM CVSS 5.4 2022-01-03
Threat Entry Updated 2024-11-21

CVE-2021-24997 - Before 1 Plugin

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

PLUGIN Before 1

CVE-2021-24997

MEDIUM CVSS 6.5 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24967 - Before 1 Plugin

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

PLUGIN Before 1

CVE-2021-24967

MEDIUM CVSS 6.1 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24753 - Before 1 Plugin

The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

PLUGIN Before 1

CVE-2021-24753

HIGH CVSS 7.2 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24902 - Before 1 Plugin

The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24902

MEDIUM CVSS 4.8 2021-12-27
Threat Entry Updated 2024-11-21

CVE-2021-24846 - Before 1 Plugin

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

PLUGIN Before 1

CVE-2021-24846

HIGH CVSS 8.8 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24907 - Before 1 Plugin

The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24907

MEDIUM CVSS 6.1 2021-12-21
Threat Entry Updated 2024-11-21

CVE-2021-24855 - Before 1 Plugin

The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2021-24855

MEDIUM CVSS 5.4 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24896 - Before 1 Plugin

The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24896

MEDIUM CVSS 4.8 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24756 - Before 1 Plugin

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

PLUGIN Before 1

CVE-2021-24756

MEDIUM CVSS 6.1 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24836 - Before 1 Plugin

The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

PLUGIN Before 1

CVE-2021-24836

MEDIUM CVSS 4.3 2021-12-13
Threat Entry Updated 2024-11-21

CVE-2021-24917 - Before 1 Plugin

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

PLUGIN Before 1

CVE-2021-24917

HIGH CVSS 7.5 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-25041 - Before 1 Plugin

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

PLUGIN Before 1

CVE-2021-25041

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24938 - Before 1 Plugin

The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24938

MEDIUM CVSS 6.1 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24718 - Before 1 Plugin

The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24718

MEDIUM CVSS 4.8 2021-12-06
Threat Entry Updated 2024-11-21

CVE-2021-24908 - Before 1 Plugin

The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

PLUGIN Before 1

CVE-2021-24908

MEDIUM CVSS 6.1 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24842 - Before 1 Plugin

The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.

PLUGIN Before 1

CVE-2021-24842

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24751 - Before 1 Plugin

The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribute, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24751

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24745 - Before 1 Plugin

The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24745

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24811 - Before 1 Plugin

The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24811

MEDIUM CVSS 4.8 2021-11-29
Scroll to top