Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 481-500 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-25038 - Before 2 Plugin

The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-25038

MEDIUM CVSS 6.1 2022-03-07
Threat Entry Updated 2024-11-21

CVE-2022-0411 - Before 2 Plugin

The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

PLUGIN Before 2

CVE-2022-0411

HIGH CVSS 8.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24920 - Before 2 Plugin

The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2021-24920

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-4222 - Before 2 Plugin

The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

PLUGIN Before 2

CVE-2021-4222

MEDIUM CVSS 4.8 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2021-24913 - Before 2 Plugin

The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in high privilege user, change title, description, alt text, and URL of arbitrary uploaded media.

PLUGIN Before 2

CVE-2021-24913

MEDIUM CVSS 4.3 2022-02-28
Threat Entry Updated 2024-11-21

CVE-2022-0255 - Before 2 Plugin

The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue

PLUGIN Before 2

CVE-2022-0255

HIGH CVSS 7.2 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0288 - Before 2 Plugin

The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-0288

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0252 - Before 2 Plugin

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-0252

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25100 - Before 2 Plugin

The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in the Donation Forms dashboard, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25100

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25099 - Before 2 Plugin

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25099

MEDIUM CVSS 6.1 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2021-25060 - Before 2 Plugin

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

PLUGIN Before 2

CVE-2021-25060

MEDIUM CVSS 5.4 2022-02-21
Threat Entry Updated 2024-11-21

CVE-2022-0208 - Before 2 Plugin

The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2022-0208

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0201 - Before 2 Plugin

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2022-0201

MEDIUM CVSS 6.1 2022-02-14
Threat Entry Updated 2024-11-21

CVE-2022-0149 - Before 2 Plugin

The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vulnerability in the woo_ce admin page.

PLUGIN Before 2

CVE-2022-0149

MEDIUM CVSS 6.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2022-0148 - Before 2 Plugin

The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

PLUGIN Before 2

CVE-2022-0148

MEDIUM CVSS 5.4 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25114 - Before 2 Plugin

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

PLUGIN Before 2

CVE-2021-25114

CRITICAL CVSS 9.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25108 - Before 2 Plugin

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

PLUGIN Before 2

CVE-2021-25108

HIGH CVSS 7.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25106 - Before 2 Plugin

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25106

MEDIUM CVSS 5.4 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25103 - Before 2 Plugin

The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY

PLUGIN Before 2

CVE-2021-25103

MEDIUM CVSS 4.7 2022-02-07
Scroll to top