Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 801-820 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24271 - Before 1 Plugin

The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24271

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24270 - Before 1 Plugin

The “DeTheme Kit for Elementor” WordPress Plugin before 1.5.5.5 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24270

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24268 - Before 1 Plugin

The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24268

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24265 - Before 1 Plugin

The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24265

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24264 - Before 1 Plugin

The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24264

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24262 - Before 1 Plugin

The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24262

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24261 - Before 1 Plugin

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24261

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24259 - Before 1 Plugin

The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24259

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24272 - Before 1 Plugin

The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24272

MEDIUM CVSS 4.3 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24256 - Before 1 Plugin

The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

PLUGIN Before 1

CVE-2021-24256

MEDIUM CVSS 5.4 2021-05-05
Threat Entry Updated 2024-11-21

CVE-2021-24238 - Before 1 Plugin

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter.

PLUGIN Before 1

CVE-2021-24238

MEDIUM CVSS 6.5 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24237 - Before 1 Plugin

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue.

PLUGIN Before 1

CVE-2021-24237

MEDIUM CVSS 6.1 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24233 - Before 1 Plugin

The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.

PLUGIN Before 1

CVE-2021-24233

MEDIUM CVSS 6.1 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24232 - Before 1 Plugin

The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue

PLUGIN Before 1

CVE-2021-24232

MEDIUM CVSS 5.4 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24242 - Before 1 Plugin

The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowing high privilege users to include any local php file

PLUGIN Before 1

CVE-2021-24242

LOW CVSS 3.8 2021-04-22
Threat Entry Updated 2024-11-21

CVE-2021-24229 - Before 1 Plugin

The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to update the pledge level required by Patreon subscribers to access a given attachment. This action is accessible for user accounts with the ‘manage_options’ privilege (i.e.., only administrators). Unfortunately, one of the parameters used in this AJAX endpoint is not sanitized before being printed back to the user, so the risk it represents is the same as the previous XSS vulnerability.

PLUGIN Before 1

CVE-2021-24229

CRITICAL CVSS 9.6 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24228 - Before 1 Plugin

The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using their Patreon account. Unfortunately, some of the error logging logic behind the scene allowed user-controlled input to be reflected on the login page, unsanitized.

PLUGIN Before 1

CVE-2021-24228

CRITICAL CVSS 9.6 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24230 - Before 1 Plugin

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user metadata on the victim’s account once visited. If exploited, this bug can be used to overwrite the “wp_capabilities” meta, which contains the affected user account’s roles and privileges. Doing this would essentially lock them out of the site, blocking them from accessing paid content.

PLUGIN Before 1

CVE-2021-24230

HIGH CVSS 8.1 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24231 - Before 1 Plugin

The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Patreon by visiting a specially crafted link.

PLUGIN Before 1

CVE-2021-24231

MEDIUM CVSS 6.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24215 - Before 1 Plugin

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

PLUGIN Before 1

CVE-2021-24215

CRITICAL CVSS 9.8 2021-04-12
Scroll to top