Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total664
Critical42
High116
Medium490
Reset
Showing 541-560 of 664 records
Threat Entry Updated 2024-11-21

CVE-2021-24883 - Before 2 Plugin

The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24883

MEDIUM CVSS 5.4 2021-11-29
Threat Entry Updated 2024-11-21

CVE-2021-24758 - Before 2 Plugin

The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

PLUGIN Before 2

CVE-2021-24758

HIGH CVSS 8.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24802 - Before 2 Plugin

The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack

PLUGIN Before 2

CVE-2021-24802

MEDIUM CVSS 6.5 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24776 - Before 2 Plugin

The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PLUGIN Before 2

CVE-2021-24776

MEDIUM CVSS 4.3 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24844 - Before 2 Plugin

The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

PLUGIN Before 2

CVE-2021-24844

HIGH CVSS 7.2 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24832 - Before 2 Plugin

The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Before 2

CVE-2021-24832

MEDIUM CVSS 4.3 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24783 - Before 2 Plugin

The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.

PLUGIN Before 2

CVE-2021-24783

MEDIUM CVSS 6.5 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24721 - Before 2 Plugin

The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed to an extension ending in .php, resulting in authenticated "translator" users being able to inject PHP code into files ending with .php in web accessible locations.

PLUGIN Before 2

CVE-2021-24721

MEDIUM CVSS 6.5 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24798 - Before 2 Plugin

The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue

PLUGIN Before 2

CVE-2021-24798

MEDIUM CVSS 6.1 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24710 - Before 2 Plugin

The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24710

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24575 - Before 2 Plugin

The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple subscribers/students to teachers and above.

PLUGIN Before 2

CVE-2021-24575

HIGH CVSS 8.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24664 - Before 2 Plugin

The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.

PLUGIN Before 2

CVE-2021-24664

MEDIUM CVSS 4.8 2021-11-08
Threat Entry Updated 2024-11-21

CVE-2021-24813 - Before 2 Plugin

The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2021-24813

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24793 - Before 2 Plugin

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Before 2

CVE-2021-24793

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24781 - Before 2 Plugin

The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)

PLUGIN Before 2

CVE-2021-24781

MEDIUM CVSS 4.3 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24682 - Before 2 Plugin

The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 2

CVE-2021-24682

MEDIUM CVSS 5.4 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24722 - Before 2 Plugin

The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Before 2

CVE-2021-24722

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24624 - Before 2 Plugin

The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks

PLUGIN Before 2

CVE-2021-24624

MEDIUM CVSS 4.8 2021-11-01
Threat Entry Updated 2024-11-21

CVE-2021-24769 - Before 2 Plugin

The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection

PLUGIN Before 2

CVE-2021-24769

HIGH CVSS 7.2 2021-10-25
Threat Entry Updated 2024-11-21

CVE-2021-24779 - Before 2 Plugin

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.

PLUGIN Before 2

CVE-2021-24779

MEDIUM CVSS 6.5 2021-10-25
Scroll to top