Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 661-680 of 837 records
Threat Entry Updated 2026-01-30

CVE-2021-24749 - Before 1 Plugin

The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.

PLUGIN Before 1

CVE-2021-24749

MEDIUM CVSS 4.3 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24894 - Before 1 Plugin

The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when an authenticated user submit such rating and the reviews are set to be displayed on the post/page

PLUGIN Before 1

CVE-2021-24894

MEDIUM CVSS 6.5 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24873 - Before 1 Plugin

The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attributes in the Student Registration page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24873

MEDIUM CVSS 6.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24882 - Before 1 Plugin

The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and Gallery "Title" fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 1

CVE-2021-24882

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24641 - Before 1 Plugin

The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

PLUGIN Before 1

CVE-2021-24641

HIGH CVSS 8.1 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24644 - Before 1 Plugin

The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

PLUGIN Before 1

CVE-2021-24644

HIGH CVSS 7.5 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24703 - Before 1 Plugin

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

PLUGIN Before 1

CVE-2021-24703

MEDIUM CVSS 5.7 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24812 - Before 1 Plugin

The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.

PLUGIN Before 1

CVE-2021-24812

MEDIUM CVSS 5.4 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24729 - Before 1 Plugin

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.

PLUGIN Before 1

CVE-2021-24729

MEDIUM CVSS 5.4 2021-11-23
Threat Entry Updated 2026-01-23

CVE-2021-24713 - Before 1 Plugin

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2021-24713

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24700 - Before 1 Plugin

The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 1

CVE-2021-24700

MEDIUM CVSS 4.8 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24668 - Before 1 Plugin

The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

PLUGIN Before 1

CVE-2021-24668

MEDIUM CVSS 4.3 2021-11-23
Threat Entry Updated 2024-11-21

CVE-2021-24854 - Before 1 Plugin

The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could allow users with a role as low as Contributor perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24854

MEDIUM CVSS 5.4 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24856 - Before 1 Plugin

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24856

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24815 - Before 1 Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24815

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24853 - Before 1 Plugin

The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR Redirects

PLUGIN Before 1

CVE-2021-24853

MEDIUM CVSS 4.3 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24796 - Before 1 Plugin

The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins

PLUGIN Before 1

CVE-2021-24796

MEDIUM CVSS 6.1 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24598 - Before 1 Plugin

The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege users to perform Cross Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24598

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24827 - Before 1 Plugin

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

PLUGIN Before 1

CVE-2021-24827

CRITICAL CVSS 9.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24791 - Before 1 Plugin

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

PLUGIN Before 1

CVE-2021-24791

HIGH CVSS 7.2 2021-11-08
Scroll to top