Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 701-720 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24744 - Before 1 Plugin

The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

PLUGIN Before 1

CVE-2021-24744

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24653 - Before 1 Plugin

The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 1

CVE-2021-24653

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24515 - Before 1 Plugin

The Video Gallery WordPress plugin before 1.1.5 does not escape the Title and Description of the videos in a gallery before outputting them in attributes, leading to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-24515

MEDIUM CVSS 4.8 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24414 - Before 1 Plugin

The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

PLUGIN Before 1

CVE-2021-24414

MEDIUM CVSS 5.4 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24752 - Before 1 Plugin

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before…

PLUGIN Before 1

CVE-2021-24752

MEDIUM CVSS 5.7 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24760 - Before 1 Plugin

The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24760

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24684 - Before 1 Plugin

The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via OS Command Injection when invoking Ghostscript.

PLUGIN Before 1

CVE-2021-24684

HIGH CVSS 8.8 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24735 - Before 1 Plugin

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.

PLUGIN Before 1

CVE-2021-24735

MEDIUM CVSS 6.5 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24743 - Before 1 Plugin

The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS.

PLUGIN Before 1

CVE-2021-24743

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24734 - Before 1 Plugin

The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 1

CVE-2021-24734

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24732 - Before 1 Plugin

The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

PLUGIN Before 1

CVE-2021-24732

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24740 - Before 1 Plugin

The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 1

CVE-2021-24740

MEDIUM CVSS 4.8 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24736 - Before 1 Plugin

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

PLUGIN Before 1

CVE-2021-24736

MEDIUM CVSS 4.8 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24413 - Before 1 Plugin

The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

PLUGIN Before 1

CVE-2021-24413

MEDIUM CVSS 5.4 2021-10-18
Threat Entry Updated 2024-11-21

CVE-2021-24683 - Before 1 Plugin

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24683

MEDIUM CVSS 5.4 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24709 - Before 1 Plugin

The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-24709

MEDIUM CVSS 4.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24546 - Before 1 Plugin

The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

PLUGIN Before 1

CVE-2021-24546

HIGH CVSS 8.8 2021-10-11
Threat Entry Updated 2024-11-21

CVE-2021-24679 - Before 1 Plugin

The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24679

MEDIUM CVSS 6.1 2021-10-04
Scroll to top