Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 501-520 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-25095 - Before 2 Plugin

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

PLUGIN Before 2

CVE-2021-25095

HIGH CVSS 7.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25077 - Before 2 Plugin

The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25077

MEDIUM CVSS 6.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25084 - Before 2 Plugin

The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example

PLUGIN Before 2

CVE-2021-25084

MEDIUM CVSS 4.3 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24879 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

PLUGIN Before 2

CVE-2021-24879

HIGH CVSS 8.8 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24843 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.

PLUGIN Before 2

CVE-2021-24843

MEDIUM CVSS 6.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24878 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24878

MEDIUM CVSS 6.1 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24880 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24880

MEDIUM CVSS 5.4 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-24839 - Before 2 Plugin

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be affected as well.

PLUGIN Before 2

CVE-2021-24839

HIGH CVSS 7.5 2022-02-07
Threat Entry Updated 2024-11-21

CVE-2021-25063 - Before 2 Plugin

The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25063

MEDIUM CVSS 6.1 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24919 - Before 2 Plugin

The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

PLUGIN Before 2

CVE-2021-24919

HIGH CVSS 8.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-24686 - Before 2 Plugin

The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in an attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24686

MEDIUM CVSS 4.8 2022-02-01
Threat Entry Updated 2024-11-21

CVE-2021-25083 - Before 2 Plugin

The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

PLUGIN Before 2

CVE-2021-25083

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25078 - Before 2 Plugin

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

PLUGIN Before 2

CVE-2021-25078

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25015 - Before 2 Plugin

The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-25015

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25008 - Before 2 Plugin

The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-25008

MEDIUM CVSS 6.1 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24968 - Before 2 Plugin

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions

PLUGIN Before 2

CVE-2021-24968

MEDIUM CVSS 5.7 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-24965 - Before 2 Plugin

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

PLUGIN Before 2

CVE-2021-24965

MEDIUM CVSS 5.4 2022-01-24
Threat Entry Updated 2024-11-21

CVE-2021-25061 - Before 2 Plugin

The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page.

PLUGIN Before 2

CVE-2021-25061

MEDIUM CVSS 5.4 2022-01-17
Threat Entry Updated 2024-11-21

CVE-2021-25053 - Before 2 Plugin

The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 2

CVE-2021-25053

HIGH CVSS 8.8 2022-01-10
Threat Entry Updated 2024-11-21

CVE-2021-25052 - Before 2 Plugin

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

PLUGIN Before 2

CVE-2021-25052

HIGH CVSS 8.8 2022-01-10
Scroll to top