Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total837
Critical42
High141
Medium628
Reset
Showing 821-837 of 837 records
Threat Entry Updated 2024-11-21

CVE-2021-24227 - Before 1 Plugin

The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attacker could leak important internal files like wp-config.php, which contains database credentials and cryptographic keys used in the generation of nonces and cookies.

PLUGIN Before 1

CVE-2021-24227

HIGH CVSS 7.5 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24225 - Before 1 Plugin

The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue

PLUGIN Before 1

CVE-2021-24225

MEDIUM CVSS 5.4 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24219 - Before 1 Plugin

The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive Apprentice WordPress plugin before 2.3.9.4, Thrive Visual Editor WordPress plugin before 2.6.7.4, Thrive Dashboard WordPress plugin before 2.3.9.3, Thrive Ovation WordPress plugin before 2.4.5, Thrive Clever Widgets WordPress plugin before 1.57.1 and Rise by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, Luxe by…

PLUGIN Before 1

CVE-2021-24219

MEDIUM CVSS 5.3 2021-04-12
Threat Entry Updated 2024-11-21

CVE-2021-24209 - Before 1 Plugin

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

PLUGIN Before 1

CVE-2021-24209

HIGH CVSS 7.2 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24210 - Before 1 Plugin

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.

PLUGIN Before 1

CVE-2021-24210

MEDIUM CVSS 6.1 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24208 - Before 1 Plugin

The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML, including JavaScript, into pages via the “Raw HTML” widget and the “Custom HTML” widgets (though the custom HTML widget requires sending a crafted request - it appears that this widget uses some form of client side validation but not server side validation), all of which are added via the “page_builder_data” parameter when performing the “wppb_page_save” AJAX action. It is also possible to insert malicious JavaScript via the “wppb_page_css” parameter (this can be…

PLUGIN Before 1

CVE-2021-24208

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24207 - Before 1 Plugin

By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to any and all posts pages - user roles must be specifically blocked from editing posts and pages.

PLUGIN Before 1

CVE-2021-24207

MEDIUM CVSS 4.3 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24184 - Before 1 Plugin

Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprotected, allowing students to modify course information and elevate their privileges among many other actions.

PLUGIN Before 1

CVE-2021-24184

HIGH CVSS 8.8 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24186 - Before 1 Plugin

The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

PLUGIN Before 1

CVE-2021-24186

MEDIUM CVSS 6.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24185 - Before 1 Plugin

The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

PLUGIN Before 1

CVE-2021-24185

MEDIUM CVSS 6.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24183 - Before 1 Plugin

The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

PLUGIN Before 1

CVE-2021-24183

MEDIUM CVSS 6.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24182 - Before 1 Plugin

The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.3 was vulnerable to UNION based SQL injection that could be exploited by students.

PLUGIN Before 1

CVE-2021-24182

MEDIUM CVSS 6.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24181 - Before 1 Plugin

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

PLUGIN Before 1

CVE-2021-24181

MEDIUM CVSS 6.5 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24196 - Before 1 Plugin

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized

PLUGIN Before 1

CVE-2021-24196

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24168 - Before 1 Plugin

The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

PLUGIN Before 1

CVE-2021-24168

MEDIUM CVSS 5.4 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24155 - Before 1 Plugin

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

PLUGIN Before 1

CVE-2021-24155

HIGH CVSS 7.2 2021-04-05
Threat Entry Updated 2024-11-21

CVE-2021-24125 - Before 1 Plugin

Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+)

PLUGIN Before 1

CVE-2021-24125

HIGH CVSS 7.2 2021-03-18
Scroll to top