Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 761-780 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24442 - Before 1 Plugin

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

PLUGIN Before 1

CVE-2021-24442

CRITICAL CVSS 9.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24441 - Before 1 Plugin

The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue

PLUGIN Before 1

CVE-2021-24441

HIGH CVSS 8.0 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24439 - Before 1 Plugin

The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.

PLUGIN Before 1

CVE-2021-24439

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24424 - Before 1 Plugin

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24424

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24421 - Before 1 Plugin

The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24421

MEDIUM CVSS 5.4 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24440 - Before 1 Plugin

The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard

PLUGIN Before 1

CVE-2021-24440

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24419 - Before 1 Plugin

The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification settings before outputting them back in the page, allowing high privilege users to set XSS payload on them and leading to stored Cross-Site Scripting issues.

PLUGIN Before 1

CVE-2021-24419

MEDIUM CVSS 4.8 2021-07-12
Threat Entry Updated 2024-11-21

CVE-2021-24406 - Before 1 Plugin

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

PLUGIN Before 1

CVE-2021-24406

MEDIUM CVSS 6.1 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24494 - Before 1 Plugin

The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling a contact form for example. The XSS will be executed in the context of a logged in admin viewing the Activity tab of the plugin.

PLUGIN Before 1

CVE-2021-24494

MEDIUM CVSS 5.4 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24388 - Before 1 Plugin

In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output back in the page, leading to a stored Cross-Site Scripting issue. There is also no CSRF check done before saving the setting, allowing attackers to make a logged in admin set arbitrary Custom Fields, including one with XSS payload in it.

PLUGIN Before 1

CVE-2021-24388

MEDIUM CVSS 5.4 2021-07-06
Threat Entry Updated 2024-11-21

CVE-2021-24379 - Before 1 Plugin

The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not prevent them from replaying the AJAX request to add a like. This allows any user (even unauthenticated) to add unlimited like/dislike to any comment. The plugin appears to have some Restriction modes, such as Cookie Restriction, IP Restrictions, Logged In User Restriction, however, they do not prevent such attack as they only check client side

PLUGIN Before 1

CVE-2021-24379

MEDIUM CVSS 5.3 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24373 - Before 1 Plugin

The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyvalue GET parameter before outputting it in a Javascript block, leading to a reflected Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24373

MEDIUM CVSS 6.1 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24372 - Before 1 Plugin

The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['REQUEST_URI'] before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24372

MEDIUM CVSS 6.1 2021-06-21
Threat Entry Updated 2024-11-21

CVE-2021-24360 - Before 1 Plugin

The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL statement, allowing medium privilege users (contributor+) to perform Blind SQL Injection attacks

PLUGIN Before 1

CVE-2021-24360

MEDIUM CVSS 6.5 2021-06-14
Threat Entry Updated 2024-11-21

CVE-2021-24321 - Before 1 Theme

The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt_bb_listing_field_now_open, bt_bb_listing_field_my_lng, listing_list_view and bt_bb_listing_field_my_lat parameters before using them in a SQL statement, leading to SQL Injection issues

THEME Before 1

CVE-2021-24321

CRITICAL CVSS 9.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24318 - Before 1 Theme

The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.

THEME Before 1

CVE-2021-24318

MEDIUM CVSS 6.5 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24320 - Before 1 Theme

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.

THEME Before 1

CVE-2021-24320

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24329 - Before 1 Plugin

The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settings, which could lead to a Stored Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24329

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24319 - Before 1 Theme

The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue

THEME Before 1

CVE-2021-24319

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24331 - Before 1 Plugin

The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them

PLUGIN Before 1

CVE-2021-24331

MEDIUM CVSS 4.8 2021-06-01
Scroll to top