Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 781-800 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24330 - Before 1 Plugin

The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.

PLUGIN Before 1

CVE-2021-24330

MEDIUM CVSS 4.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24311 - Before 1 Plugin

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users.

PLUGIN Before 1

CVE-2021-24311

HIGH CVSS 8.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24312 - Before 1 Plugin

The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'. This is due to an incomplete fix of CVE-2021-24209.

PLUGIN Before 1

CVE-2021-24312

HIGH CVSS 7.2 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24317 - Before 1 Theme

The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation and Personal Message pages, leading to Cross-Site Scripting issues

THEME Before 1

CVE-2021-24317

MEDIUM CVSS 6.1 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24313 - Before 1 Plugin

The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.

PLUGIN Before 1

CVE-2021-24313

MEDIUM CVSS 5.4 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24310 - Before 1 Plugin

The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the gallery title, allowing high privilege users to create one with XSS payload in it, which will be triggered when another user will view the gallery list or the affected gallery in the admin dashboard. This is due to an incomplete fix of CVE-2019-16117

PLUGIN Before 1

CVE-2021-24310

MEDIUM CVSS 4.8 2021-06-01
Threat Entry Updated 2024-11-21

CVE-2021-24300 - Before 1 Plugin

The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24300

MEDIUM CVSS 6.1 2021-05-24
Threat Entry Updated 2024-11-21

CVE-2021-24326 - Before 1 Plugin

The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

PLUGIN Before 1

CVE-2021-24326

MEDIUM CVSS 5.4 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24292 - Before 1 Plugin

The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method: The “Card” widget accepts a “title_tag” parameter. Although the element control lists a fixed set of possible html tags, it is possible to send a ‘save_builder’ request with the “heading_tag” set to “script”, and the actual “title” parameter set to JavaScript to be executed within the script tags added…

PLUGIN Before 1

CVE-2021-24292

MEDIUM CVSS 5.4 2021-05-17
Threat Entry Updated 2024-11-21

CVE-2021-24195 - Before 1 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 1

CVE-2021-24195

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24291 - Before 1 Plugin

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)

PLUGIN Before 1

CVE-2021-24291

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24287 - Before 1 Plugin

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24287

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24286 - Before 1 Plugin

The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24286

MEDIUM CVSS 6.1 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24277 - Before 1 Plugin

The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues

PLUGIN Before 1

CVE-2021-24277

MEDIUM CVSS 5.4 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24191 - Before 1 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 1

CVE-2021-24191

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24190 - Before 1 Plugin

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

PLUGIN Before 1

CVE-2021-24190

HIGH CVSS 8.8 2021-05-14
Threat Entry Updated 2024-11-21

CVE-2021-24246 - Before 1 Plugin

The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues

PLUGIN Before 1

CVE-2021-24246

MEDIUM CVSS 5.4 2021-05-06
Threat Entry Updated 2024-11-21

CVE-2021-24276 - Before 1 Plugin

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24276

MEDIUM CVSS 6.1 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24275 - Before 1 Plugin

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24275

MEDIUM CVSS 6.1 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24274 - Before 1 Plugin

The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24274

MEDIUM CVSS 6.1 2021-05-05
Scroll to top