Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 681-700 of 837 records
Threat Entry Updated 2026-01-23

CVE-2021-24767 - Before 1 Plugin

The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack

PLUGIN Before 1

CVE-2021-24767

MEDIUM CVSS 6.5 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24708 - Before 1 Plugin

The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputting it in Manage Exports settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24708

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24669 - Before 1 Plugin

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

PLUGIN Before 1

CVE-2021-24669

HIGH CVSS 8.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24646 - Before 1 Plugin

The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24646

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24645 - Before 1 Plugin

The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24645

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24616 - Before 1 Plugin

The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24616

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24809 - Before 1 Plugin

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions

PLUGIN Before 1

CVE-2021-24809

HIGH CVSS 8.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24742 - Before 1 Plugin

The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.

PLUGIN Before 1

CVE-2021-24742

MEDIUM CVSS 6.5 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24808 - Before 1 Plugin

The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24808

MEDIUM CVSS 6.1 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24723 - Before 1 Plugin

The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

PLUGIN Before 1

CVE-2021-24723

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24789 - Before 1 Plugin

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 1

CVE-2021-24789

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24799 - Before 1 Plugin

The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Before 1

CVE-2021-24799

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24717 - Before 1 Plugin

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

PLUGIN Before 1

CVE-2021-24717

HIGH CVSS 8.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24685 - Before 1 Plugin

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)

PLUGIN Before 1

CVE-2021-24685

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24715 - Before 1 Plugin

The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24715

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24539 - Before 1 Plugin

The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24539

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24572 - Before 1 Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary posts

PLUGIN Before 1

CVE-2021-24572

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24570 - Before 1 Plugin

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.

PLUGIN Before 1

CVE-2021-24570

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24774 - Before 1 Plugin

The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameters before using them in a SQL statement when viewing logs, leading to SQL injections issues

PLUGIN Before 1

CVE-2021-24774

HIGH CVSS 7.2 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24699 - Before 1 Plugin

The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24699

MEDIUM CVSS 5.4 2021-10-25
Scroll to top